<?xml version="1.0" encoding="UTF-8"?>
<root>
<information>
	<iceyefiletype>rulesystem</iceyefiletype>
	<version>5.6.0.036</version>
	<date>2009-02-03</date>
	<name>系统规则</name>
	<copyright>(c)1999-2008 NSFocus</copyright>	
</information>
<sysruledesc>
  <rules>
  <rule ruleid="20874" enabled="true" group="68157738" action=" db  screen " name="HTTP协议Proxy-Authorization字段超长缓冲区溢出攻击" name_chs="HTTP协议Proxy-Authorization字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long Proxy-Authorization Field Buffer Overflow" visible="true"/><rule ruleid="30448" enabled="true" group="361766970" action=" db  screen " name="Cisco IOS ILMI SNMP共同体串访问" name_chs="Cisco IOS ILMI SNMP共同体串访问" name_eng="Cisco IOS ILMI SNMP Community String" visible="true"/><rule ruleid="30110" enabled="true" group="136315062" action=" db  screen " name="SysAdmin Magazine man.sh脚本漏洞扫描探测" name_chs="SysAdmin Magazine man.sh脚本漏洞扫描探测" name_eng="SysAdmin Magazine man.sh Script Vulnerability Detection" visible="true"/><rule ruleid="40026" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Unexplained木马建立连接" name_chs="Windows系统下Unexplained木马建立连接" name_eng="Trojan Unexplained Trojan Connectionon Windows" visible="true"/><rule ruleid="40024" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Delta Source木马通信" name_chs="Windows系统下Delta Source木马通信" name_eng="Trojan Delta Source Communication on Windows" visible="true"/><rule ruleid="30114" enabled="true" group="136315066" action=" db  screen " name="NCSA phf脚本漏洞扫描探测" name_chs="NCSA phf脚本漏洞扫描探测" name_eng="NCSA phf Script Vulnerability Detection" visible="true"/><rule ruleid="40022" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Fore木马建立连接" name_chs="Windows系统下Fore木马建立连接" name_eng="Trojan Fore Connection on Windows" visible="true"/><rule ruleid="30116" enabled="true" group="136315062" action=" db  screen " name="获取QuikStore quikstore.cfg配置文件" name_chs="获取QuikStore quikstore.cfg配置文件" name_eng="QuikStore quikstore.cfg File Disclosure" visible="true"/><rule ruleid="30441" enabled="true" group="68157743" action=" db  screen  drop " name="Microsoft IIS 5.0 .printer ISAPI扩展映射远程缓冲区溢出攻击" name_chs="Microsoft IIS 5.0 .printer ISAPI扩展映射远程缓冲区溢出攻击" name_eng="Microsoft IIS 5.0 .printer ISAPI Extension Mapping Remote Buffer Overflow" visible="true"/><rule ruleid="40607" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下WinRat木马通信" name_chs="Windows系统下WinRat木马通信" name_eng="Trojan WinRat Communication on Windows" visible="true"/><rule ruleid="40354" enabled="true" group="68157646" action=" db  screen " name="Frontpage fpsrvadm.exe文件扫描探测" name_chs="Frontpage fpsrvadm.exe文件扫描探测" name_eng="Frontpage fpsrvadm.exe File Detection" visible="true"/><rule ruleid="40604" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下War Trojan木马通信" name_chs="Windows系统下War Trojan木马通信" name_eng="Trojan War Trojan Communication on Windows" visible="true"/><rule ruleid="40351" enabled="true" group="136323126" action=" db  screen " name="PHP/FI mlog.phtml脚本漏洞扫描探测" name_chs="PHP/FI mlog.phtml脚本漏洞扫描探测" name_eng="PHP/FI mlog.phtml Script Vulnerability Detection" visible="true"/><rule ruleid="40601" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Vampire木马通信" name_chs="Windows系统下Vampire木马通信" name_eng="Trojan Vampire Communication on Windows" visible="true"/><rule ruleid="40600" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Vagrnocker木马通信" name_chs="Windows系统下Vagrnocker木马通信" name_eng="Trojan Vagrnocker Communication on Windows" visible="true"/><rule ruleid="20744" enabled="true" group="203423915" action=" db  screen " name="HiveMail远程PHP代码注入攻击" name_chs="HiveMail远程PHP代码注入攻击" name_eng="HiveMail Remote PHP Code Injection" visible="true"/><rule ruleid="20745" enabled="true" group="203423915" action=" db  screen " name="Clever Copy ID参数远程SQL注入攻击" name_chs="Clever Copy ID参数远程SQL注入攻击" name_eng="Clever Copy ID Parameter Remote SQL Injection" visible="true"/><rule ruleid="20746" enabled="true" group="203423914" action=" db  screen " name="WebspotBlogging login.php远程SQL注入攻击" name_chs="WebspotBlogging login.php远程SQL注入攻击" name_eng="WebspotBlogging login.php Remote SQL Injection" visible="true"/><rule ruleid="20747" enabled="true" group="203423915" action=" db  screen " name="eFiction远程SQL注入攻击" name_chs="eFiction远程SQL注入攻击" name_eng="eFiction Remote SQL Injection" visible="true"/><rule ruleid="20740" enabled="true" group="203423915" action=" db  screen " name="TotalCalendar多个远程文件包含攻击" name_chs="TotalCalendar多个远程文件包含攻击" name_eng="TotalCalendar multiple Remote File Inclusions" visible="true"/><rule ruleid="20741" enabled="true" group="203423914" action=" db  screen " name="Blursoft Blur6ex多个远程SQL注入攻击" name_chs="Blursoft Blur6ex多个远程SQL注入攻击" name_eng="Blursoft Blur6ex multiple Remote SQL Injections" visible="true"/><rule ruleid="20742" enabled="true" group="203423915" action=" db  screen " name="Owl Intranet Engine远程文件包含攻击" name_chs="Owl Intranet Engine远程文件包含攻击" name_eng="Owl Intranet Engine Remote File Inclusion" visible="true"/><rule ruleid="20743" enabled="true" group="203423915" action=" db  screen " name="PHPKit UNC路径远程文件包含攻击" name_chs="PHPKit UNC路径远程文件包含攻击" name_eng="PHPKit UNC Path Remote File Inclusion" visible="true"/><rule ruleid="20748" enabled="true" group="203423914" action=" db  screen " name="Website Baker远程SQL注入攻击" name_chs="Website Baker远程SQL注入攻击" name_eng="Website Baker Remote SQL Injection" visible="true"/><rule ruleid="20749" enabled="true" group="203423914" action=" db  screen " name="Edgewall Software Trac Search模块远程SQL注入攻击" name_chs="Edgewall Software Trac Search模块远程SQL注入攻击" name_eng="Edgewall Software Trac Search Module Remote SQL Injection" visible="true"/><rule ruleid="40608" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Xanadu 1.0木马通信" name_chs="Windows系统下Xanadu 1.0木马通信" name_eng="Trojan Xanadu 1.0 Communication on Windows" visible="true"/><rule ruleid="70061" enabled="true" group="209715789" action="" name="SMTP服务返回码535" name_chs="SMTP服务返回码535" name_eng="SMTP Service Returning 535" visible="false"/><rule ruleid="20520" enabled="true" group="88082475" action=" db  screen " name="MySQL/Windows CREATE FUNCTION功能引用特殊函数库攻击" name_chs="MySQL/Windows CREATE FUNCTION功能引用特殊函数库攻击" name_eng="MySQL/Windows CREATE FUNCTION Special Library Reference" visible="true"/><rule ruleid="20521" enabled="true" group="88082475" action=" db  screen " name="MySQL/Windows CREATE FUNCTION功能目录遍历加载任意库攻击" name_chs="MySQL/Windows CREATE FUNCTION功能目录遍历加载任意库攻击" name_eng="MySQL/Windows CREATE FUNCTION Directory Traversal Arbitrary Library Loading" visible="true"/><rule ruleid="20522" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows即插即用功能远程缓冲区溢出攻击" name_chs="Microsoft Windows即插即用功能远程缓冲区溢出攻击" name_eng="Microsoft Windows Plug and Play Function Remote Buffer Overflow" visible="true"/><rule ruleid="10142" enabled="true" group="78645274" action=" db  screen " name="3Com 3CDaemon TFTP保留设备名拒绝服务攻击" name_chs="3Com 3CDaemon TFTP保留设备名拒绝服务攻击" name_eng="3Com 3CDaemon TFTP Reserved Device Name Denial of Service" visible="true"/><rule ruleid="20524" enabled="true" group="203423915" action=" db  screen " name="MyBulletinBoard search.php远程SQL注入攻击" name_chs="MyBulletinBoard search.php远程SQL注入攻击" name_eng="MyBulletinBoard search.php Remote SQL Injection" visible="true"/><rule ruleid="20525" enabled="true" group="203423915" action=" db  screen " name="Woltlab Burning Board modcp.php远程SQL注入攻击" name_chs="Woltlab Burning Board modcp.php远程SQL注入攻击" name_eng="Woltlab Burning Board modcp.php Remote Code Injection" visible="true"/><rule ruleid="20526" enabled="true" group="136315051" action=" db  screen " name="Zorum prod.php远程执行命令攻击" name_chs="Zorum prod.php远程执行命令攻击" name_eng="Zorum prod.php Remote Command Execution" visible="true"/><rule ruleid="10146" enabled="true" group="138414106" action=" db  screen " name="Solaris Telnet服务远程Ctrl-D字符拒绝服务攻击" name_chs="Solaris Telnet服务远程Ctrl-D字符拒绝服务攻击" name_eng="Solaris Telnet Service Remote Ctrl-D Character Denial of Service" visible="true"/><rule ruleid="20528" enabled="true" group="203423919" action=" db  screen " name="WebCalendar send_reminders.php远程执行命令攻击" name_chs="WebCalendar send_reminders.php远程执行命令攻击" name_eng="WebCalendar send_reminders.php Remote Command Execution" visible="true"/><rule ruleid="20529" enabled="true" group="143655215" action=" db  screen " name="GNU Mailutils 0.6 imap4d SEARCH命令远程格式串溢出攻击" name_chs="GNU Mailutils 0.6 imap4d SEARCH命令远程格式串溢出攻击" name_eng="GNU Mailutils 0.6 imap4d SEARCH Command Remote Format String Buffer Overflow" visible="true"/><rule ruleid="20090" enabled="true" group="203423911" action=" db  screen " name="利用Zeroboard _head.php脚本漏洞远程执行命令" name_chs="利用Zeroboard _head.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Zeroboard _head.php Script Vulnerability" visible="true"/><rule ruleid="20091" enabled="true" group="144703787" action=" db  screen " name="BIND iquery远程缓冲区溢出攻击" name_chs="BIND iquery远程缓冲区溢出攻击" name_eng="BIND iquery Remote Buffer Overflow" visible="true"/><rule ruleid="20093" enabled="true" group="166723887" action=" db  screen " name="Solaris CDE dtspcd远程缓冲区溢出攻击" name_chs="Solaris CDE dtspcd远程缓冲区溢出攻击" name_eng="Solaris CDE dtspcd Remote Buffer Overflow" visible="true"/><rule ruleid="40184" enabled="true" group="99618887" action=" db  screen " name="Windows系统下CDK木马建立连接" name_chs="Windows系统下CDK木马建立连接" name_eng="Trojan CDK Connection on Windows" visible="true"/><rule ruleid="40189" enabled="true" group="136323126" action=" db  screen " name="PHP/FI mylog.phtml脚本漏洞扫描探测" name_chs="PHP/FI mylog.phtml脚本漏洞扫描探测" name_eng="PHP/FI mylog.phtml Script Vulnerability Detection" visible="true"/><rule ruleid="20095" enabled="true" group="203423915" action=" db  screen  drop " name="利用B2 b2edit.showposts.php脚本漏洞" name_chs="利用B2 b2edit.showposts.php脚本漏洞" name_eng="B2 b2edit.showposts.php Script Vulnerability" visible="true"/><rule ruleid="20418" enabled="true" group="99615023" action=" db  screen  drop " name="Microsoft PCT协议远程缓冲区溢出攻击" name_chs="Microsoft PCT协议远程缓冲区溢出攻击" name_eng="Microsoft PCT Protocol Remote Buffer Overflow" visible="true"/><rule ruleid="20419" enabled="true" group="136315051" action=" db  screen " name="利用psinclude.cgi脚本漏洞远程执行命令" name_chs="利用psinclude.cgi脚本漏洞远程执行命令" name_eng="Remote Command Execution via psinclude.cgi Script Vulnerability" visible="true"/><rule ruleid="20416" enabled="true" group="136315183" action=" db  screen " name="PHP Post文件上传缓冲区溢出攻击" name_chs="PHP Post文件上传缓冲区溢出攻击" name_eng="PHP Post File Upload Buffer Overflow" visible="true"/><rule ruleid="20417" enabled="true" group="70254879" action=" db  screen  drop " name="Serv-U FTP服务器LIST命令超长-l参数远程拒绝服务攻击" name_chs="Serv-U FTP服务器LIST命令超长-l参数远程拒绝服务攻击" name_eng="Serv-U FTP Server LIST Command Over-long Parameter &quot;-1&quot; Remote Denial of Service" visible="true"/><rule ruleid="20410" enabled="true" group="204472619" action=" db  screen " name="FTP服务NLST命令超长参数溢出攻击" name_chs="FTP服务NLST命令超长参数溢出攻击" name_eng="FTP Service NLST Command Over-long Parameter Buffer Overflow" visible="true"/><rule ruleid="20411" enabled="true" group="99615014" action=" db  screen " name="Windows 95/98 UNC远程溢出攻击" name_chs="Windows 95/98 UNC远程溢出攻击" name_eng="Windows 95/98 UNC Remote Buffer Overflow" visible="true"/><rule ruleid="20412" enabled="true" group="135266607" action=" db  screen " name="Apache Web Server分块畸形编码传输" name_chs="Apache Web Server分块畸形编码传输" name_eng="Apache Web Server Malicious Chunked-Encoding Transmission" visible="true"/><rule ruleid="20413" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows LSA服务远程缓冲区溢出攻击" name_chs="Microsoft Windows LSA服务远程缓冲区溢出攻击" name_eng="Microsoft Windows LSA Service Remote Buffer Overflow" visible="true" merge="[t7200,si]"/><rule ruleid="30411" enabled="true" group="136323126" action=" db  screen " name="chetcpasswd.cgi脚本漏洞扫描探测" name_chs="chetcpasswd.cgi脚本漏洞扫描探测" name_eng="chetcpasswd.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30410" enabled="true" group="203431999" action=" db  screen " name="PHP-Nuke modules.php脚本漏洞扫描探测" name_chs="PHP-Nuke modules.php脚本漏洞扫描探测" name_eng="PHP-Nuke modules.php Script Vulnerability Detection" visible="true"/><rule ruleid="30413" enabled="true" group="136323129" action=" db  screen " name="Oracle 9i应用服务程序示例脚本扫描探测" name_chs="Oracle 9i应用服务程序示例脚本扫描探测" name_eng="Oracle 9i Application Server Sample Script Detection" visible="true"/><rule ruleid="10090" enabled="true" group="99614999" action=" db  screen " name="Artisoft XtraMail远程拒绝服务攻击" name_chs="Artisoft XtraMail远程拒绝服务攻击" name_eng="Artisoft XtraMail Remote Denial of Service" visible="true"/><rule ruleid="30415" enabled="true" group="136323125" action=" db  screen " name="Active PHP Bookmarks脚本漏洞扫描探测" name_chs="Active PHP Bookmarks脚本漏洞扫描探测" name_eng="Active PHP Bookmarks Script Vulnerability Detection" visible="true"/><rule ruleid="30414" enabled="true" group="136323126" action=" db  screen " name="H-Sphere WebShell脚本漏洞扫描探测" name_chs="H-Sphere WebShell脚本漏洞扫描探测" name_eng="H-Sphere WebShell Script Vulnerability Detection" visible="true"/><rule ruleid="30417" enabled="true" group="203431998" action=" db  screen " name="PHP-Nuke mailattach.php脚本漏洞扫描探测" name_chs="PHP-Nuke mailattach.php脚本漏洞扫描探测" name_eng="PHP-Nuke mailattach.php Script Vulnerability Detection" visible="true"/><rule ruleid="30416" enabled="true" group="203431989" action=" db  screen " name="myPHPNuke system_footer.php脚本漏洞扫描探测" name_chs="myPHPNuke system_footer.php脚本漏洞扫描探测" name_eng="myPHPNuke system_footer.php Script Vulnerability Detection" visible="true"/><rule ruleid="30419" enabled="true" group="136315066" action=" db  screen " name="利用EditTag edittag.cgi脚本漏洞远程读取任意文件" name_chs="利用EditTag edittag.cgi脚本漏洞远程读取任意文件" name_eng="Remote Arbitrary File Reading via EditTag edittag.cgi Script Vulnerability" visible="true"/><rule ruleid="30418" enabled="true" group="136323126" action=" db  screen " name="psunami.cgi脚本漏洞扫描探测" name_chs="psunami.cgi脚本漏洞扫描探测" name_eng="psunami.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="10098" enabled="true" group="70256667" action=" db  screen  drop " name="Windows NT IIS/4.0 FTP NLST命令远程拒绝服务攻击" name_chs="Windows NT IIS/4.0 FTP NLST命令远程拒绝服务攻击" name_eng="Windows NT IIS/4.0 FTP NLST Command Remote Denial of Service" visible="true"/><rule ruleid="30329" enabled="true" group="136315066" action=" db  screen " name="YaBB YaBB.pl脚本漏洞攻击" name_chs="YaBB YaBB.pl脚本漏洞攻击" name_eng="YaBB YaBB.pl Script Vulnerability" visible="true"/><rule ruleid="30328" enabled="true" group="136315066" action=" db  screen " name="利用SIX-webboard generate.cgi脚本漏洞远程遍历目录" name_chs="利用SIX-webboard generate.cgi脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via SIX-webboard generate.cgi Script Vulnerability" visible="true"/><rule ruleid="40369" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht客户端连接检查" name_chs="DDOS工具Stacheldraht客户端连接检查" name_eng="DDOS Stacheldraht Client Connection Deteciton" visible="true"/><rule ruleid="30323" enabled="true" group="136323126" action=" db  screen " name="ans.pl脚本漏洞扫描探测" name_chs="ans.pl脚本漏洞扫描探测" name_eng="ans.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30322" enabled="true" group="136315062" action=" db  screen " name="store.cgi脚本漏洞扫描利用" name_chs="store.cgi脚本漏洞扫描利用" name_eng="store.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30321" enabled="true" group="203423930" action=" db  screen " name="Lotus Domino Server远程目录遍历攻击" name_chs="Lotus Domino Server远程目录遍历攻击" name_eng="Lotus Domino Server Remote Directory Traversal" visible="true"/><rule ruleid="30320" enabled="true" group="136315062" action=" db  screen " name="Tatantella TTAWebTop.CGI脚本漏洞扫描利用" name_chs="Tatantella TTAWebTop.CGI脚本漏洞扫描利用" name_eng="Tatantella TTAWebTop.CGI Script Vulnerability Detection" visible="true"/><rule ruleid="30327" enabled="true" group="136323130" action=" db  screen " name="SIX-webboard generate.cgi脚本漏洞扫描探测" name_chs="SIX-webboard generate.cgi脚本漏洞扫描探测" name_eng="SIX-webboard generate.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30326" enabled="true" group="136315062" action=" db  screen " name="agora.cgi脚本漏洞扫描利用" name_chs="agora.cgi脚本漏洞扫描利用" name_eng="agora.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30325" enabled="true" group="136323130" action=" db  screen " name="AHG search.cgi脚本漏洞扫描探测" name_chs="AHG search.cgi脚本漏洞扫描探测" name_eng="AHG search.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30324" enabled="true" group="136315062" action=" db  screen " name="利用ans.pl脚本远程漏洞遍历目录" name_chs="利用ans.pl脚本远程漏洞遍历目录" name_eng="Remote Directory Traversal via ans.pl Script" visible="true"/><rule ruleid="40614" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.P@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.P@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.P@mm" visible="true"/><rule ruleid="20250" enabled="true" group="203431993" action=" db  screen " name="Allaire ColdFusion未公开CFML标记漏洞扫描探测" name_chs="Allaire ColdFusion未公开CFML标记漏洞扫描探测" name_eng="Allaire ColdFusion Undocumented CFML Tags Vulnerability Detection" visible="true"/><rule ruleid="30206" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.ypserv服务存在性TCP扫描探测" name_chs="Solaris rpc.ypserv服务存在性TCP扫描探测" name_eng="Solaris rpc.ypserv Service TCP Detection" visible="true"/><rule ruleid="40742" enabled="true" group="99618891" action=" db  screen " name="Windows系统下近墨者木马通信" name_chs="Windows系统下近墨者木马通信" name_eng="Trojan Jinmozhe Communication on Windows" visible="true"/><rule ruleid="40743" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware Gator下载安装程序" name_chs="Windows系统下Adware Gator下载安装程序" name_eng="Adware Gator Downloading Installer on Windows" visible="true"/><rule ruleid="40740" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware AproposMedia下载安装程序" name_chs="Windows系统下Adware AproposMedia下载安装程序" name_eng="Adware AproposMedia Downloading Installer on Windows" visible="true"/><rule ruleid="40741" enabled="true" group="69210191" action=" db  screen " name="Windows系统下黑客帝国ASP后门访问" name_chs="Windows系统下黑客帝国ASP后门访问" name_eng="Hacker's Empire ASP Backdoor on Windows" visible="true"/><rule ruleid="30529" enabled="true" group="203423929" action=" db  screen " name="Caucho Resin viewfile获取脚本源码攻击" name_chs="Caucho Resin viewfile获取脚本源码攻击" name_eng="Caucho Resin viewfile Script Source Code Disclosure" visible="true"/><rule ruleid="40747" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware GameSpy Arcade下载安装程序" name_chs="Windows系统下Adware GameSpy Arcade下载安装程序" name_eng="Adware GameSpy Arcade Downloading Installer on Windows" visible="true"/><rule ruleid="40744" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware TopMoxie下载安装程序" name_chs="Windows系统下Adware TopMoxie下载安装程序" name_eng="Adware TopMoxie Downloading Installer on Windows" visible="true"/><rule ruleid="40745" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware InstantAccess下载安装程序" name_chs="Windows系统下Adware InstantAccess下载安装程序" name_eng="Adware InstantAccess Downloading Installer on Windows" visible="true"/><rule ruleid="30525" enabled="true" group="69206198" action=" db  screen " name="Alibaba alibaba.pl脚本漏洞扫描利用" name_chs="Alibaba alibaba.pl脚本漏洞扫描利用" name_eng="Alibaba alibaba.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30524" enabled="true" group="88088638" action=" db  screen " name="Microsoft SQL Server预验证过程远程缓冲区漏洞探测" name_chs="Microsoft SQL Server预验证过程远程缓冲区漏洞探测" name_eng="Microsoft SQL Server Pre-authentication Process Buffer Vulnerability Detection" visible="true"/><rule ruleid="30255" enabled="true" group="203431994" action=" db  screen " name="vBulletin Calendar.php脚本漏洞扫描探测" name_chs="vBulletin Calendar.php脚本漏洞扫描探测" name_eng="vBulletin Calendar.php Script Vulnerability Detection" visible="true"/><rule ruleid="40749" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Lyyshell木马通信" name_chs="Windows系统下Lyyshell木马通信" name_eng="Trojan Lyyshell Communication on Windows" visible="true"/><rule ruleid="30253" enabled="true" group="203423930" action=" db  screen " name="Tomcat 4.x远程获取JSP源代码攻击" name_chs="Tomcat 4.x远程获取JSP源代码攻击" name_eng="Tomcat 4.x Remote JSP Source Code Disclosure" visible="true"/><rule ruleid="30520" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－ACK扫描" name_chs="服务器端口扫描－ACK扫描" name_eng="Server Port Scan - ACK Scan" visible="true"/><rule ruleid="30523" enabled="true" group="203423934" action=" db  screen " name="Allaire JRun Servlet畸形请求远程获取源码攻击" name_chs="Allaire JRun Servlet畸形请求远程获取源码攻击" name_eng="Allaire JRun Servlet Malformed Request Source Code Disclosure" visible="true"/><rule ruleid="30250" enabled="true" group="136315066" action=" db  screen " name="访问&quot;/_pages&quot;获取Oracle 9iAS JSP源码攻击" name_chs="访问&quot;/_pages&quot;获取Oracle 9iAS JSP源码攻击" name_eng="Oracle 9iAS JSP Source Code Disclosure via &quot;/_pages&quot;" visible="true"/><rule ruleid="40327" enabled="true" group="99618895" action=" db  screen " name="Windows系统下Bluefire木马连接建立" name_chs="Windows系统下Bluefire木马连接建立" name_eng="Trojan Bluefire Connection on Windows" visible="true"/><rule ruleid="40328" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下冰河木马通信" name_chs="Windows系统下冰河木马通信" name_eng="Trojan Glacier Trojan Communication on Windows" visible="true"/><rule ruleid="40568" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下The Prayer木马通信" name_chs="Windows系统下The Prayer木马通信" name_eng="Trojan The Prayer Communication on Windows" visible="true"/><rule ruleid="40569" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下PrivatePort木马通信" name_chs="Windows系统下PrivatePort木马通信" name_eng="Trojan PrivatePort Communication on Windows" visible="true"/><rule ruleid="50099" enabled="true" group="99745885" action=" db  screen " name="网络游戏平台中国游戏中心登录" name_chs="网络游戏平台中国游戏中心登录" name_eng="Online Game Platform &quot;chinagames.net&quot; Login" visible="true"/><rule ruleid="50098" enabled="true" group="99680349" action=" db  screen " name="Windows系统远程管理工具Remote Administrator用户认证" name_chs="Windows系统远程管理工具Remote Administrator用户认证" name_eng="Windows Remote Management Tool Remote Administrator Authentication" visible="true"/><rule ruleid="40562" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下OOTLT木马通信" name_chs="Windows系统下OOTLT木马通信" name_eng="Trojan OOTLT Communication on Windows" visible="true"/><rule ruleid="40563" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Optix木马通信" name_chs="Windows系统下Optix木马通信" name_eng="Trojan Optix Communication on Windows" visible="true"/><rule ruleid="40560" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Olive木马通信" name_chs="Windows系统下Olive木马通信" name_eng="Trojan Olive Communication on Windows" visible="true"/><rule ruleid="40561" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下One木马通信" name_chs="Windows系统下One木马通信" name_eng="Trojan One Communication on Windows" visible="true"/><rule ruleid="40566" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Phoenix木马通信" name_chs="Windows系统下Phoenix木马通信" name_eng="Trojan Phoenix Communication on Windows" visible="true"/><rule ruleid="40567" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下PitFall木马通信" name_chs="Windows系统下PitFall木马通信" name_eng="Trojan PitFall Communication on Windows" visible="true"/><rule ruleid="40564" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Oxon木马通信" name_chs="Windows系统下Oxon木马通信" name_eng="Trojan Oxon Communication on Windows" visible="true"/><rule ruleid="40565" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下PC Invader木马通信" name_chs="Windows系统下PC Invader木马通信" name_eng="Trojan PC Invader Communication on Windows" visible="true"/><rule ruleid="30360" enabled="true" group="69206198" action=" db  screen " name="ION ion-p.exe脚本漏洞扫描利用" name_chs="ION ion-p.exe脚本漏洞扫描利用" name_eng="ION ion-p.exe Script Vulnerability Detection" visible="true"/><rule ruleid="20865" enabled="true" group="68157738" action=" db  screen " name="mIRC IRC URL缓冲区溢出攻击" name_chs="mIRC IRC URL缓冲区溢出攻击" name_eng="mIRC IRC URL Buffer Overflow" visible="true"/><rule ruleid="40299" enabled="true" group="88146015" action=" db  screen " name="Microsoft SQL 客户端SA用户默认空口令连接" name_chs="Microsoft SQL 客户端SA用户默认空口令连接" name_eng="Microsoft SQL Client SA User Default Null Password Connection" visible="true"/><rule ruleid="40458" enabled="true" group="99876911" action=" db  screen " name="Windows系统下利用Novarg/Mydoom后门上传执行程序" name_chs="Windows系统下利用Novarg/Mydoom后门上传执行程序" name_eng="Executable Upload via Novarg/Mydoom Backdoor on Windows" visible="true" merge="[t300,si]"/><rule ruleid="20867" enabled="true" group="68157738" action=" db  screen " name="HTTP协议Accept-Language字段超长缓冲区溢出攻击" name_chs="HTTP协议Accept-Language字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long Accept-Language Field Buffer Overflow" visible="true"/><rule ruleid="50075" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN Messenger用户登录" name_chs="即时通信软件MSN Messenger用户登录" name_eng="Instant Messaging Software MSN Messenger User Login" visible="true"/><rule ruleid="50074" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户登录" name_chs="即时通信软件ICQ用户登录" name_eng="Instant Messaging Software ICQ User Login" visible="true"/><rule ruleid="50077" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具BitTorrent获取文件信息" name_chs="P2P文件共享工具BitTorrent获取文件信息" name_eng="P2P File Sharing Tool BitTorrent Obtainning File Information" visible="true" merge="[t3600,si]"/><rule ruleid="40459" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.D@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.D@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.D@mm" visible="true" merge="[t7200,si]"/><rule ruleid="50071" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k连接服务器" name_chs="P2P文件共享工具eDonkey/ed2k连接服务器" name_eng="P2P File Sharing Tool eDonkey/ed2k Server Connection" visible="true"/><rule ruleid="50070" enabled="true" group="68190293" action=" db  screen " name="Web服务TRACK方法请求" name_chs="Web服务TRACK方法请求" name_eng="Web Service TRACK Method Request" visible="true"/><rule ruleid="50073" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k请求文件片断(TCP)" name_chs="P2P文件共享工具eDonkey/ed2k请求文件片断(TCP)" name_eng="P2P File Sharing Tool eDonkey/ed2k File Request Fragment (TCP)" visible="true"/><rule ruleid="50072" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k搜索文件" name_chs="P2P文件共享工具eDonkey/ed2k搜索文件" name_eng="P2P File Sharing Tool eDonkey/ed2k Searching Files" visible="true"/><rule ruleid="50079" enabled="true" group="99745885" action=" db  screen " name="网络游戏星际争霸（Starcraft）客户端连接服务器" name_chs="网络游戏星际争霸（Starcraft）客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;Starcraft&quot;" visible="true"/><rule ruleid="50078" enabled="true" group="99745885" action=" db  screen " name="网络游戏反恐精英（CS）客户端连接服务器" name_chs="网络游戏反恐精英（CS）客户端连接服务器" name_eng="Connection from Client to Server of Online Game CS" visible="true"/><rule ruleid="40457" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Novarg/Mydoom蠕虫及其变种Mydoom.U病毒邮件" name_chs="SMTP服务发送Novarg/Mydoom蠕虫及其变种Mydoom.U病毒邮件" name_eng="SMTP Service Sending Mails with Novarg/Mydoom and Variant Mydoom.U" visible="true" merge="[t7200,si]"/><rule ruleid="40633" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AP@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AP@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AP@mm" visible="true"/><rule ruleid="20860" enabled="true" group="70254890" action=" db  screen " name="FTP服务器SIZE命令超长参数远程缓冲区溢出攻击" name_chs="FTP服务器SIZE命令超长参数远程缓冲区溢出攻击" name_eng="FTP Server SIZE Command Over-Long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20863" enabled="true" group="68157738" action=" db  screen " name="XMPlay播放列表文件远程栈溢出攻击" name_chs="XMPlay播放列表文件远程栈溢出攻击" name_eng="XMPlay Playlist File Remote Stack Overflow" visible="true"/><rule ruleid="20572" enabled="true" group="203423915" action=" db  screen " name="MyBB showteam.php远程SQL注入攻击" name_chs="MyBB showteam.php远程SQL注入攻击" name_eng="MyBB showteam.php Remote SQL Injection" visible="true"/><rule ruleid="30227" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.ttdbserverd服务存在性UDP扫描探测" name_chs="Solaris rpc.ttdbserverd服务存在性UDP扫描探测" name_eng="Solaris rpc.ttdbserverd Service UDP Detection" visible="true"/><rule ruleid="20731" enabled="true" group="300941610" action=" db  screen " name="Cisco CallManager SIP 超长To字段缓冲区溢出攻击" name_chs="Cisco CallManager SIP 超长To字段缓冲区溢出攻击" name_eng="Cisco CallManager SIP Over-long To Field Buffer Overflow" visible="true"/><rule ruleid="20730" enabled="true" group="300941610" action=" db  screen " name="Cisco CallManager SIP超长主机名UDP远程缓冲区溢出攻击" name_chs="Cisco CallManager SIP超长主机名UDP远程缓冲区溢出攻击" name_eng="Cisco CallManager SIP Over-long Host Name UDP Remote Buffer Overflow" visible="true"/><rule ruleid="20733" enabled="true" group="99615019" action=" db  screen " name="Symantec Antivirus Rtvscan.exe远程栈溢出攻击" name_chs="Symantec Antivirus Rtvscan.exe远程栈溢出攻击" name_eng="Symantec Antivirus Rtvscan.exe Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20732" enabled="true" group="300941610" action=" db  screen " name="Cisco CallManager SIP超长主机名TCP远程缓冲区溢出攻击" name_chs="Cisco CallManager SIP超长主机名TCP远程缓冲区溢出攻击" name_eng="Cisco CallManager SIP Over-long Host Name TCP Remote Buffer Overflow" visible="true"/><rule ruleid="20735" enabled="true" group="99616811" action=" db  screen " name="Microsoft IE DHTML引擎竞争条件攻击" name_chs="Microsoft IE DHTML引擎竞争条件攻击" name_eng="Microsoft IE DHTML Engine Race Condition" visible="true"/><rule ruleid="20734" enabled="true" group="75497771" action=" db  screen " name="Foxmail Serve MAIL FROM远程缓冲区溢出攻击" name_chs="Foxmail Serve MAIL FROM远程缓冲区溢出攻击" name_eng="Foxmail Serve MAIL FROM Remote Buffer Overflow" visible="true"/><rule ruleid="20737" enabled="true" group="99615019" action=" db  screen " name="Netscape NSS库SSLV2畸形Hello消息远程缓冲区溢出攻击" name_chs="Netscape NSS库SSLV2畸形Hello消息远程缓冲区溢出攻击" name_eng="Netscape NSS Lib SSLV2 Malformed Hello Message Remote Buffer Overflow" visible="true"/><rule ruleid="20736" enabled="true" group="233832747" action=" db  screen " name="SIP畸形URI远程缓冲区溢出攻击" name_chs="SIP畸形URI远程缓冲区溢出攻击" name_eng="SIP Malformed URI Remote Buffer Overflow" visible="true"/><rule ruleid="20739" enabled="true" group="203423915" action=" db  screen " name="EQdkp dbal.php远程文件包含攻击" name_chs="EQdkp dbal.php远程文件包含攻击" name_eng="EQdkp dbal.php Remote File Inclusion" visible="true"/><rule ruleid="20738" enabled="true" group="99615019" action=" db  screen " name="Apache Mod_SSL/Apache-SSL远程缓冲区溢出攻击" name_chs="Apache Mod_SSL/Apache-SSL远程缓冲区溢出攻击" name_eng="Apache Mod_SSL/Apache-SSL Remote Buffer Overflow" visible="true"/><rule ruleid="10152" enabled="true" group="300943386" action=" db  screen " name="H.225协议destinationAddress email-ID数据畸形" name_chs="H.225协议destinationAddress email-ID数据畸形" name_eng="H.225 Protocol destinationAddress email-ID Malformed Data" visible="true"/><rule ruleid="10153" enabled="true" group="300943386" action=" db  screen " name="H.225协议sourceAddress序列数据畸形" name_chs="H.225协议sourceAddress序列数据畸形" name_eng="H.225 Protocol sourceAddress Sequence Malformed Data" visible="true"/><rule ruleid="10150" enabled="true" group="300943386" action=" db  screen " name="Q.931协议Calling Party Number Length数据畸形" name_chs="Q.931协议Calling Party Number Length数据畸形" name_eng="Q.931 Protocol Calling Party Number Length Malformed Data" visible="true"/><rule ruleid="10151" enabled="true" group="300943386" action=" db  screen " name="H.225协议DestinationAddress序列数据畸形" name_chs="H.225协议DestinationAddress序列数据畸形" name_eng="H.225 Protocol DestinationAddress Sequence Malformed Data" visible="true"/><rule ruleid="10156" enabled="true" group="300943386" action=" db  screen " name="H.225协议Destination AliasAddress e164Number数据畸形" name_chs="H.225协议Destination AliasAddress e164Number数据畸形" name_eng="H.225 Protocol Destination AliasAddress e164Number Malformed Data" visible="true"/><rule ruleid="10157" enabled="true" group="300943386" action=" db  screen " name="H.225协议DestinationAddress H323-ID数据畸形" name_chs="H.225协议DestinationAddress H323-ID数据畸形" name_eng="H.225 Protocol DestinationAddress H323-ID Malformed Data" visible="true"/><rule ruleid="20089" enabled="true" group="136315051" action=" db  screen " name="利用WEBgais websendmail脚本漏洞远程执行命令" name_chs="利用WEBgais websendmail脚本漏洞远程执行命令" name_eng="Remote Code Execution via WEBgais websendmail Script Vulnerability" visible="true"/><rule ruleid="10155" enabled="true" group="300943386" action=" db  screen " name="H.225协议Destination AliasAddress Choice扩展选项数据畸形" name_chs="H.225协议Destination AliasAddress Choice扩展选项数据畸形" name_eng="H.225 Protocol Destination AliasAddress Choice Extended Option Malformed Data" visible="true"/><rule ruleid="20087" enabled="true" group="136315051" action=" db  screen  drop " name="利用Matt Wright textcounter.pl脚本漏洞远程执行命令" name_chs="利用Matt Wright textcounter.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via Matt Wright textcounter.pl Script Vulnerability" visible="true"/><rule ruleid="20086" enabled="true" group="136315051" action=" db  screen " name="利用NCSA phf脚本漏洞远程执行命令" name_chs="利用NCSA phf脚本漏洞远程执行命令" name_eng="Remote Code Execution via  NCSA phf Script Vulnerability" visible="true"/><rule ruleid="10158" enabled="true" group="78645274" action=" db  screen " name="TFTPD32远程格式串文件名拒绝服务攻击" name_chs="TFTPD32远程格式串文件名拒绝服务攻击" name_eng="TFTPD32 Username Remote Format String Denial of Service" visible="true"/><rule ruleid="20084" enabled="true" group="136315051" action=" db  screen " name="利用IRIX handler脚本漏洞远程执行命令" name_chs="利用IRIX handler脚本漏洞远程执行命令" name_eng="Remote Code Execution via IRIX handler Script Vulnerability" visible="true"/><rule ruleid="20083" enabled="true" group="136315051" action=" db  screen  drop " name="利用FormMail formmail.pl脚本漏洞远程执行命令" name_chs="利用FormMail formmail.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via FormMail formmail.pl Script Vulnerability" visible="true"/><rule ruleid="20082" enabled="true" group="136315051" action=" db  screen  drop " name="利用Hylafax faxsurvey脚本漏洞远程执行命令" name_chs="利用Hylafax faxsurvey脚本漏洞远程执行命令" name_eng="Remote Code Execution via Hylafax faxsurvey Script Vulnerability" visible="true"/><rule ruleid="20081" enabled="true" group="136315051" action=" db  screen " name="利用CGISCRIPT.NET csNews.cgi脚本漏洞远程执行命令" name_chs="利用CGISCRIPT.NET csNews.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CGISCRIPT.NET csNews.cgi Script Vulnerability" visible="true"/><rule ruleid="20080" enabled="true" group="136315051" action=" db  screen " name="利用CGISCRIPT.NET csLiveSupport.cgi脚本漏洞远程执行命令" name_chs="利用CGISCRIPT.NET csLiveSupport.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CGISCRIPT.NET csLiveSupport.cgi Script Vulnerability" visible="true"/><rule ruleid="20649" enabled="true" group="203423915" action=" db  screen " name="WowBB view_user.php远程SQL注入攻击" name_chs="WowBB view_user.php远程SQL注入攻击" name_eng="WowBB view_user.php Remote SQL Injection" visible="true"/><rule ruleid="20648" enabled="true" group="99615019" action=" db  screen " name="eStara Softphone SIP SDP请求远程缓冲区溢出攻击" name_chs="eStara Softphone SIP SDP请求远程缓冲区溢出攻击" name_eng="eStara Softphone SIP SDP Request Remote Buffer Overflow" visible="true"/><rule ruleid="20645" enabled="true" group="203423915" action=" db  screen " name="RaXnet Cacti远程文件包含执行命令攻击" name_chs="RaXnet Cacti远程文件包含执行命令攻击" name_eng="RaXnet Cacti Remote File Inclusion Code Execution" visible="true"/><rule ruleid="20644" enabled="true" group="203423919" action=" db  screen " name="miniBB news.php远程文件包含攻击" name_chs="miniBB news.php远程文件包含攻击" name_eng="miniBB news.php Remote File Inclusion" visible="true"/><rule ruleid="20647" enabled="true" group="203423915" action=" db  screen " name="osTicket include_dir变量远程文件包含攻击" name_chs="osTicket include_dir变量远程文件包含攻击" name_eng="osTicket include_dir Variable Remote File Inclusion" visible="true"/><rule ruleid="20646" enabled="true" group="203423915" action=" db  screen " name="PmWiki pmwiki.php远程文件包含攻击" name_chs="PmWiki pmwiki.php远程文件包含攻击" name_eng="PmWiki pmwiki.php Remote File Inclusion" visible="true"/><rule ruleid="20641" enabled="true" group="99615019" action=" db  screen " name="Microsoft Windows Server驱动Mailslot远程堆溢出攻击" name_chs="Microsoft Windows Server驱动Mailslot远程堆溢出攻击" name_eng="Microsoft Windows Server Driver Mailslot Remote Heap Overflow" visible="true"/><rule ruleid="20640" enabled="true" group="203423915" action=" db  screen " name="Mambo/Joomla mosConfig_absolute_path远程文件包含攻击" name_chs="Mambo/Joomla mosConfig_absolute_path远程文件包含攻击" name_eng="Mambo/Joomla mosConfig_absolute_path Remote File Inclusion" visible="true"/><rule ruleid="20643" enabled="true" group="300941611" action=" db  screen " name="D-Link路由器UPNP远程缓冲区溢出攻击" name_chs="D-Link路由器UPNP远程缓冲区溢出攻击" name_eng="D-Link Rounter UPNP Remote Buffer Overflow" visible="true"/><rule ruleid="20642" enabled="true" group="97517871" action=" db  screen " name="Microsoft Windows DHCP Client服务ACK应答处理缓冲区溢出攻击" name_chs="Microsoft Windows DHCP Client服务ACK应答处理缓冲区溢出攻击" name_eng="Microsoft Windows DHCP Client Service ACK Response Handling Buffer Overflow" visible="true"/><rule ruleid="40178" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下NetSphere木马建立连接" name_chs="Windows系统下NetSphere木马建立连接" name_eng="Trojan NetSphere Connection on Windows" visible="true"/><rule ruleid="40174" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Hack a tack木马建立连接" name_chs="Windows系统下Hack a tack木马建立连接" name_eng="Trojan Hack a tack Connection on Windows" visible="true"/><rule ruleid="40176" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下WinCrash 1.0木马建立连接" name_chs="Windows系统下WinCrash 1.0木马建立连接" name_eng="Trojan WinCrash 1.0 Connection on Windows" visible="true"/><rule ruleid="40171" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht服务器回应堵塞" name_chs="DDOS工具Stacheldraht服务器回应堵塞" name_eng="DDOS Tool Stacheldraht Server Response Block" visible="true"/><rule ruleid="40173" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下DonaldDick木马建立连接" name_chs="Windows系统下DonaldDick木马建立连接" name_eng="Trojan DonaldDick Connection on Windows" visible="true"/><rule ruleid="40172" enabled="true" group="99618895" action=" db  screen " name="Windows系统下的PhaseZero木马连接建立" name_chs="Windows系统下的PhaseZero木马连接建立" name_eng="Trojan PhaseZero Connection on Windows" visible="true"/><rule ruleid="20469" enabled="true" group="203423919" action=" db  screen " name="PHPNews sendtofriend.php远程SQL注入攻击" name_chs="PHPNews sendtofriend.php远程SQL注入攻击" name_eng="PHPNews sendtofriend.php Remote SQL Injection" visible="true"/><rule ruleid="20468" enabled="true" group="203423915" action=" db  screen " name="PowerPortal index.php远程SQL注入攻击" name_chs="PowerPortal index.php远程SQL注入攻击" name_eng="PowerPortal index.php Remote SQL Injection" visible="true"/><rule ruleid="20399" enabled="true" group="99615791" action=" db  screen  drop " name="Windows系统下Witty蠕虫传播" name_chs="Windows系统下Witty蠕虫传播" name_eng="Windows Witty Worm Propagation" visible="true"/><rule ruleid="20398" enabled="true" group="69206315" action=" db  screen " name="利用MDaemon form2raw.cgi CGI脚本漏洞溢出攻击" name_chs="利用MDaemon form2raw.cgi CGI脚本漏洞溢出攻击" name_eng="Buffer Overflow via MDaemon form2raw.cgi CGI Script Vulnerability" visible="true"/><rule ruleid="20461" enabled="true" group="203423915" action=" db  screen " name="Phorum follow.php远程SQL注入攻击" name_chs="Phorum follow.php远程SQL注入攻击" name_eng="Phorum follow.php Remote SQL Injection" visible="true"/><rule ruleid="20460" enabled="true" group="99615019" action=" db  screen " name="Oracle 8i TNS Listener缓冲区溢出攻击" name_chs="Oracle 8i TNS Listener缓冲区溢出攻击" name_eng="Oracle 8i TNS Listener Buffer Overflow" visible="true"/><rule ruleid="20463" enabled="true" group="203423919" action=" db  screen " name="miniBB bb_func_usernfo.php远程SQL注入攻击" name_chs="miniBB bb_func_usernfo.php远程SQL注入攻击" name_eng="miniBB bb_func_usernfo.php Remote SQL Injection" visible="true"/><rule ruleid="20462" enabled="true" group="203423919" action=" db  screen " name="vBulletin Forum last.php远程SQL注入攻击" name_chs="vBulletin Forum last.php远程SQL注入攻击" name_eng="vBulletin Forum last.php Remote SQL Injection" visible="true"/><rule ruleid="20465" enabled="true" group="203423919" action=" db  screen " name="利用phpBB admin_cash.php CGI脚本漏洞远程执行命令" name_chs="利用phpBB admin_cash.php CGI脚本漏洞远程执行命令" name_eng="Remote Command Execution via phpBB admin_cash.php CGI Script Vulnerability" visible="true"/><rule ruleid="20396" enabled="true" group="70254895" action=" db  screen  drop " name="Serv-U FTP服务器MDTM命令远程缓冲区溢出攻击" name_chs="Serv-U FTP服务器MDTM命令远程缓冲区溢出攻击" name_eng="Serv-U FTP Server MDTM Command Remote Buffer Overflow" visible="true"/><rule ruleid="20467" enabled="true" group="203423919" action=" db  screen " name="Invision Power Board index.php远程SQL注入攻击" name_chs="Invision Power Board index.php远程SQL注入攻击" name_eng="Invision Power Board index.php Remote SQL Injection" visible="true"/><rule ruleid="20466" enabled="true" group="203423919" action=" db  screen  drop " name="phpBB URL编码远程任意命令执行攻击" name_chs="phpBB URL编码远程任意命令执行攻击" name_eng="phpBB URL Encoding Remote Arbitrary Command Execution" visible="true"/><rule ruleid="30402" enabled="true" group="136315062" action=" db  screen " name="利用Home Free search.cgi脚本漏洞目录遍历攻击" name_chs="利用Home Free search.cgi脚本漏洞目录遍历攻击" name_eng="Directory Traversal via Home Free search.cgi Script Vulnerability" visible="true"/><rule ruleid="30403" enabled="true" group="136315066" action=" db  screen " name="利用Moreover.com cached_feed.cgi脚本远程遍历目录" name_chs="利用Moreover.com cached_feed.cgi脚本远程遍历目录" name_eng="Remote Directory Traversal via Moreover.com cached_feed.cgi Script" visible="true"/><rule ruleid="30400" enabled="true" group="136315066" action=" db  screen " name="利用PHP-Nuke CGI脚本漏洞获取目录信息" name_chs="利用PHP-Nuke CGI脚本漏洞获取目录信息" name_eng="Directory Information Disclosure via PHP-Nuke CGI Script Vulnerability" visible="true"/><rule ruleid="30401" enabled="true" group="69214266" action=" db  screen " name="利用Trend Micro OfficeScan jdkRqNotify.exe脚本漏洞" name_chs="利用Trend Micro OfficeScan jdkRqNotify.exe脚本漏洞" name_eng="Trend Micro OfficeScan jdkRqNotify.exe Script Vulnerability" visible="true"/><rule ruleid="10088" enabled="true" group="69206171" action=" db  screen " name="利用Microsoft Outlook Web Access漏洞进行拒绝服务攻击" name_chs="利用Microsoft Outlook Web Access漏洞进行拒绝服务攻击" name_eng="Denial of Service via Microsoft Outlook Web Access Vulnerability" visible="true"/><rule ruleid="10089" enabled="true" group="137365535" action=" db  screen " name="ProFTPD STAT命令远程拒绝服务攻击" name_chs="ProFTPD STAT命令远程拒绝服务攻击" name_eng="ProFTPD STAT Command Remote Denial of Service" visible="true"/><rule ruleid="30404" enabled="true" group="136315066" action=" db  screen " name="Moreover.com cached_feed.cgi脚本漏洞扫描探测" name_chs="Moreover.com cached_feed.cgi脚本漏洞扫描探测" name_eng="Moreover.com cached_feed.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30405" enabled="true" group="202407995" action=" db  screen " name="通过Web服务访问Netscape SuiteSpot管理员口令文件" name_chs="通过Web服务访问Netscape SuiteSpot管理员口令文件" name_eng="Access to Netscape SuiteSpot Admin Password File via Web Service" visible="true"/><rule ruleid="10084" enabled="true" group="368052247" action=" db  screen " name="Ascend系列路由器UDP/9端口拒绝服务攻击" name_chs="Ascend系列路由器UDP/9端口拒绝服务攻击" name_eng="Ascend Routers Port UDP/9 Denial of Service" visible="true"/><rule ruleid="10086" enabled="true" group="136315035" action=" db  screen " name="利用HP Openview Manager OpenView5.exe程序漏洞拒绝服务攻击" name_chs="利用HP Openview Manager OpenView5.exe程序漏洞拒绝服务攻击" name_eng="Denial of Service via HP Openview Manager OpenView5.exe Vulnerability" visible="true"/><rule ruleid="30409" enabled="true" group="136323130" action=" db  screen " name="Open WebMail openwebmail-shared.pl脚本漏洞扫描探测" name_chs="Open WebMail openwebmail-shared.pl脚本漏洞扫描探测" name_eng="Open WebMail openwebmail-shared.pl Script Vulnerability Detection" visible="true"/><rule ruleid="10080" enabled="true" group="337641627" action=" db  screen " name="Cisco VoIP Phone流量统计请求拒绝服务攻击" name_chs="Cisco VoIP Phone流量统计请求拒绝服务攻击" name_eng="Cisco VoIP Phone Traffic Statistic Request Denial of Service" visible="true"/><rule ruleid="10081" enabled="true" group="70256667" action=" db  screen " name="TransSoft FTP-Broker远程拒绝服务攻击" name_chs="TransSoft FTP-Broker远程拒绝服务攻击" name_eng="TransSoft FTP-Broker Remote Denial of Service" visible="true"/><rule ruleid="10082" enabled="true" group="203423899" action=" db  screen " name="Real Networks RealServer远程拒绝服务攻击" name_chs="Real Networks RealServer远程拒绝服务攻击" name_eng="Real Networks RealServer Remote Denial of Service" visible="true"/><rule ruleid="40313" enabled="true" group="68157743" action=" db  screen " name="Microsoft IIS 4.0/5.0 .asp ISAPI扩展远程缓冲区溢出攻击" name_chs="Microsoft IIS 4.0/5.0 .asp ISAPI扩展远程缓冲区溢出攻击" name_eng="Microsoft IIS 4.0/5.0 .asp ISAPI Extension Remote Buffer Overflow" visible="true"/><rule ruleid="20266" enabled="true" group="69206187" action=" db  screen " name="Oracle 9i应用服务器无需授权访问管理目录漏洞攻击" name_chs="Oracle 9i应用服务器无需授权访问管理目录漏洞攻击" name_eng="Unauthorized Access to Oracle 9i Application Server Admin Directory" visible="true"/><rule ruleid="20263" enabled="true" group="166723879" action=" db  screen " name="AIX pdnsd远程缓冲区溢出攻击" name_chs="AIX pdnsd远程缓冲区溢出攻击" name_eng="AIX pdnsd Remote Buffer Overflow" visible="true"/><rule ruleid="20262" enabled="true" group="136315055" action=" db  screen " name="利用NETCODE book.cgi脚本漏洞远程执行命令" name_chs="利用NETCODE book.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via NETCODE book.cgi Script Vulnerability" visible="true"/><rule ruleid="20067" enabled="true" group="141558063" action=" db  screen " name="SSH1守护程序crc32补偿攻击检测安全漏洞攻击" name_chs="SSH1守护程序crc32补偿攻击检测安全漏洞攻击" name_eng="SSH1 Daemon crc32 Compensation Attack Detection" visible="true"/><rule ruleid="20060" enabled="true" group="83886383" action=" db  screen " name="Solaris ypbind TCP远程缓冲区溢出攻击" name_chs="Solaris ypbind TCP远程缓冲区溢出攻击" name_eng="Solaris ypbind TCP Remote Buffer Overflow" visible="true"/><rule ruleid="20068" enabled="true" group="137365551" action=" db  screen  drop " name="Wu-ftpd畸形文件名扩展请求远程堆溢出攻击" name_chs="Wu-ftpd畸形文件名扩展请求远程堆溢出攻击" name_eng="Wu-ftpd Malformed Filename Extension Request Remote Heap Overflow" visible="true"/><rule ruleid="30248" enabled="true" group="136347710" action=" db  screen " name="通过Web服务访问Oracle 9i默认配置文件XSQLConfig.xml" name_chs="通过Web服务访问Oracle 9i默认配置文件XSQLConfig.xml" name_eng="Access to Oracle 9i Default Config File XSQLConfig.xml via Web Service" visible="true"/><rule ruleid="30249" enabled="true" group="136347710" action=" db  screen " name="通过Web服务访问Oracle 9i默认配置文件soapConfig.xml" name_chs="通过Web服务访问Oracle 9i默认配置文件soapConfig.xml" name_eng="Access to Oracle 9i Default Config File soapConfig.xml via Web Service" visible="true"/><rule ruleid="40779" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows Media Player畸形PNG块文档邮件附件传播" name_chs="Microsoft Windows Media Player畸形PNG块文档邮件附件传播" name_eng="Microsoft Windows Media Player Malformed PNG Chunk Document Attachment Propagation" visible="true"/><rule ruleid="40778" enabled="true" group="75563082" action=" db  screen " name="Microsoft Excel畸形STYLE格式文档邮件附件传播" name_chs="Microsoft Excel畸形STYLE格式文档邮件附件传播" name_eng="Microsoft Excel Malformed STYLE Format Document Attachemtn Propagation" visible="true"/><rule ruleid="40777" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows恶意.lnk文件邮件附件传播" name_chs="Microsoft Windows恶意.lnk文件邮件附件传播" name_eng="Microsoft Windows Malicious .lnk Document Attachment Propagation" visible="true"/><rule ruleid="40776" enabled="true" group="99680330" action=" db  screen " name="Windows系统下Adware Speedbar网络通信" name_chs="Windows系统下Adware Speedbar网络通信" name_eng="Windows Adware Speedbar Network Communication" visible="true"/><rule ruleid="40775" enabled="true" group="71307337" action=" db  screen " name="Microsoft Windows 2000 telnet执行NTLM认证" name_chs="Microsoft Windows 2000 telnet执行NTLM认证" name_eng="Microsoft Windows 2000 telnet NTLM Authentication" visible="true"/><rule ruleid="30535" enabled="true" group="203423930" action=" db  screen " name="Oracle Reports Server获取任意文件部分内容攻击" name_chs="Oracle Reports Server获取任意文件部分内容攻击" name_eng="Oracle Reports Server Partial File Content Disclosure" visible="true"/><rule ruleid="40773" enabled="true" group="99680330" action=" db  screen " name="Windows系统下Adware Conspy下载更新" name_chs="Windows系统下Adware Conspy下载更新" name_eng="Windows Adware Conspy Download Upgrade" visible="true"/><rule ruleid="30245" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－SYNFIN扫描" name_chs="服务器端口扫描－SYNFIN扫描" name_eng="Server Port Scan - SYNFIN Scan" visible="true"/><rule ruleid="30246" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－NULL扫描" name_chs="服务器端口扫描－NULL扫描" name_eng="Server Port Scan - NULL Scan" visible="true"/><rule ruleid="30531" enabled="true" group="69206202" action=" db  screen " name="Caucho Resin Windows远程目录遍历攻击" name_chs="Caucho Resin Windows远程目录遍历攻击" name_eng="Caucho Resin Windows Remote Directory Traversal" visible="true"/><rule ruleid="40557" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下NOSecure木马通信" name_chs="Windows系统下NOSecure木马通信" name_eng="Trojan NOSecure Communication on Windows" visible="true"/><rule ruleid="40556" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Nirvana木马通信" name_chs="Windows系统下Nirvana木马通信" name_eng="Trojan Nirvana Communication on Windows" visible="true"/><rule ruleid="40555" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下New Silencer木马通信" name_chs="Windows系统下New Silencer木马通信" name_eng="Trojan New Silencer Communication on Windows" visible="true"/><rule ruleid="40554" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Network Terrorist木马通信" name_chs="Windows系统下Network Terrorist木马通信" name_eng="Trojan Network Terrorist Communication on Windows" visible="true"/><rule ruleid="40553" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下NetTrash木马通信" name_chs="Windows系统下NetTrash木马通信" name_eng="Trojan NetTrash Communication on Windows" visible="true"/><rule ruleid="40552" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Taxi木马通信" name_chs="Windows系统下Net Taxi木马通信" name_eng="Trojan Net Taxi Communication on Windows" visible="true"/><rule ruleid="40551" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Controller木马通信" name_chs="Windows系统下Net Controller木马通信" name_eng="Trojan Net Controller Communication on Windows" visible="true"/><rule ruleid="40550" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Raider木马通信" name_chs="Windows系统下Net Raider木马通信" name_eng="Trojan Net Raider Communication on Windows" visible="true"/><rule ruleid="40308" enabled="true" group="154206298" action=" db  screen " name="RLOGIN服务root用户认证" name_chs="RLOGIN服务root用户认证" name_eng="RLOGIN Service root User Authentication" visible="true"/><rule ruleid="40559" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Osiris木马通信" name_chs="Windows系统下Osiris木马通信" name_eng="Trojan Osiris Communication on Windows" visible="true"/><rule ruleid="40558" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Oblivion木马通信" name_chs="Windows系统下Oblivion木马通信" name_eng="Trojan Oblivion Communication on Windows" visible="true"/><rule ruleid="40795" enabled="true" group="99615818" action=" db  screen " name="Windows系统下熊猫烧香蠕虫病毒刷计数器操作" name_chs="Windows系统下熊猫烧香蠕虫病毒刷计数器操作" name_eng="Nimaya Refreshing the Counter on Windows" visible="true"/><rule ruleid="40794" enabled="true" group="99615818" action=" db  screen " name="Windows系统下熊猫烧香蠕虫病毒解析恶意网站域名" name_chs="Windows系统下熊猫烧香蠕虫病毒解析恶意网站域名" name_eng="Nimaya Parsing Malicious Website Domain Name on Windows System" visible="true"/><rule ruleid="40797" enabled="true" group="270534729" action=" db  screen " name="Netgear FVS318绕过URL访问过滤攻击" name_chs="Netgear FVS318绕过URL访问过滤攻击" name_eng="Netgear FVS318 URL Sanitization Bypass" visible="true"/><rule ruleid="40796" enabled="true" group="99615818" action=" db  screen " name="Windows系统下熊猫烧香蠕虫病毒下载恶意代码" name_chs="Windows系统下熊猫烧香蠕虫病毒下载恶意代码" name_eng="Nimaya Downloading Malicious Code on Windows" visible="true"/><rule ruleid="40791" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows图形渲染引擎恶意WMF格式文档邮件附件传播" name_chs="Microsoft Windows图形渲染引擎恶意WMF格式文档邮件附件传播" name_eng="Microsoft Windows Graphics Rendering Engine WMF Format Attachment Propagation" visible="true"/><rule ruleid="40790" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE FTP URI处理漏洞恶意命令代码邮件引用" name_chs="Microsoft IE FTP URI处理漏洞恶意命令代码邮件引用" name_eng="Microsoft IE FTP URI Processing Vulnerability Mail" visible="true"/><rule ruleid="40793" enabled="true" group="99680330" action=" db  screen " name="Microsoft Windows 2000 RPC服务畸形回应" name_chs="Microsoft Windows 2000 RPC服务畸形回应" name_eng="Microsoft Windows 2000 RPC Service Malformed Response" visible="true"/><rule ruleid="40792" enabled="true" group="99680330" action=" db  screen " name="Microsoft Windows 2000 RPC服务畸形请求" name_chs="Microsoft Windows 2000 RPC服务畸形请求" name_eng="Microsoft Windows 2000 RPC Service Malformed Requests" visible="true"/><rule ruleid="50080" enabled="true" group="99745885" action=" db  screen " name="即时通信软件网易泡泡用户登录" name_chs="即时通信软件网易泡泡用户登录" name_eng="Instant Messaging Software POPO User Login" visible="true"/><rule ruleid="50081" enabled="true" group="99745885" action=" db  screen " name="即时通信软件新浪UC用户登录" name_chs="即时通信软件新浪UC用户登录" name_eng="Instant Messaging Software Sina UC User Login" visible="true"/><rule ruleid="50082" enabled="true" group="209780829" action=" db  screen " name="SMTP服务暴力猜测用户名口令" name_chs="SMTP服务暴力猜测用户名口令" name_eng="SMTP Service User Password Brute Forcce" visible="true"/><rule ruleid="50083" enabled="true" group="99680349" action=" db  screen " name="Windows系统远程管理工具终端服务用户登录" name_chs="Windows系统远程管理工具终端服务用户登录" name_eng="Windows Remote Management Tool Terminal Service User Login" visible="true"/><rule ruleid="40799" enabled="true" group="68223050" action=" db  screen " name="Macromedia Shockwave 10 SWDIR.DLL多个ActiveX控件远程拒绝服务攻击" name_chs="Macromedia Shockwave 10 SWDIR.DLL多个ActiveX控件远程拒绝服务攻击" name_eng="Macromedia Shockwave 10 SWDIR.DLL ActiveX Control Remote Denial of Service" visible="true"/><rule ruleid="40798" enabled="true" group="136380473" action=" db  screen " name="Nokia Electronic Documentation连接重定向功能利用" name_chs="Nokia Electronic Documentation连接重定向功能利用" name_eng="Nokia Electronic Documentation Connection Redirection Exploitation" visible="true"/><rule ruleid="50086" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN发现非法信息" name_chs="即时通信软件MSN发现非法信息" name_eng="Instant Messaging Software MSN Illegal Information" visible="true"/><rule ruleid="50087" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN发现传送可疑文件" name_chs="即时通信软件MSN发现传送可疑文件" name_eng="Instant Messaging Software MSN Sending Suspicious Files" visible="true"/><rule ruleid="20894" enabled="true" group="68157738" action=" db  screen " name="Microsoft SQL Server sqldmo.dll ActiveX控件缓冲区溢出攻击" name_chs="Microsoft SQL Server sqldmo.dll ActiveX控件缓冲区溢出攻击" name_eng="Microsoft SQL Server sqldmo.dll ActiveX Control Buffer Overflow" visible="true"/><rule ruleid="30180" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp3.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp3.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp3.htr File" visible="true"/><rule ruleid="30335" enabled="true" group="136315066" action=" db  screen " name="HyperSeek hsx.cgi脚本漏洞扫描利用" name_chs="HyperSeek hsx.cgi脚本漏洞扫描利用" name_eng="HyperSeek hsx.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30336" enabled="true" group="136323130" action=" db  screen " name="CGIScript.net cspassword.cgi脚本漏洞扫描探测" name_chs="CGIScript.net cspassword.cgi脚本漏洞扫描探测" name_eng="CGIScript.net cspassword.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30337" enabled="true" group="136323130" action=" db  screen " name="password.cgi.tmp文件扫描探测" name_chs="password.cgi.tmp文件扫描探测" name_eng="password.cgi.tmp File Detection" visible="true"/><rule ruleid="30330" enabled="true" group="203423925" action=" db  screen " name="IBM Net.Data document.d2w脚本漏洞扫描利用" name_chs="IBM Net.Data document.d2w脚本漏洞扫描利用" name_eng="IBM Net.Data document.d2w Script Vulnerability Detection" visible="true"/><rule ruleid="30331" enabled="true" group="69206198" action=" db  screen " name="Alibaba tst.bat脚本漏洞扫描利用" name_chs="Alibaba tst.bat脚本漏洞扫描利用" name_eng="Alibaba tst.bat Script Vulnerability Detection" visible="true"/><rule ruleid="30332" enabled="true" group="136315062" action=" db  screen " name="cal_make.pl脚本漏洞扫描利用" name_chs="cal_make.pl脚本漏洞扫描利用" name_eng="cal_make.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30333" enabled="true" group="136315062" action=" db  screen " name="利用pagelog.cgi脚本遍历目录" name_chs="利用pagelog.cgi脚本遍历目录" name_eng="Directory Traversal via pagelog.cgi Script" visible="true"/><rule ruleid="30338" enabled="true" group="136323126" action=" db  screen " name="pagelog.cgi脚本漏洞扫描探测" name_chs="pagelog.cgi脚本漏洞扫描探测" name_eng="pagelog.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30339" enabled="true" group="136315062" action=" db  screen " name="classifieds.cgi脚本漏洞扫描利用" name_chs="classifieds.cgi脚本漏洞扫描利用" name_eng="classifieds.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40301" enabled="true" group="361824349" action=" db  screen " name="SNMP服务试图使用默认public口令访问" name_chs="SNMP服务试图使用默认public口令访问" name_eng="SNMP Service Access Attempt with Default public Password" visible="true" merge="[t86400,si]"/><rule ruleid="30222" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 5.0 +.htr文件泄漏漏洞获取源代码攻击" name_chs="Microsoft IIS 5.0 +.htr文件泄漏漏洞获取源代码攻击" name_eng="Source Code Disclosure from Microsoft IIS 5.0 +.htr File" visible="true"/><rule ruleid="30223" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage orders.htm文件获取服务器信息" name_chs="访问Frontpage orders.htm文件获取服务器信息" name_eng="Server Information Disclosure from Frontpage orders.htm File" visible="true"/><rule ruleid="40420" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问匿名管道" name_chs="Windows SMB访问匿名管道" name_eng="Windows SMB Accessing Anonymous Pipe" visible="true" merge="[t7200,si,di]"/><rule ruleid="40427" enabled="true" group="99618890" action=" db  screen  drop " name="Windows系统下Dagger 1.4.0木马服务端返回系统信息" name_chs="Windows系统下Dagger 1.4.0木马服务端返回系统信息" name_eng="Trojan Dagger 1.4.0 Server Returning System Information on Windows" visible="true"/><rule ruleid="40426" enabled="true" group="99618890" action=" db  screen " name="Windows系统下Dagger 1.4.0木马客户端发送控制信号" name_chs="Windows系统下Dagger 1.4.0木马客户端发送控制信号" name_eng="Trojan Dagger 1.4.0 Client Sending Control Signals on Windows" visible="true"/><rule ruleid="40425" enabled="true" group="154141259" action=" db  screen " name="RLOGIN服务用户认证 失败" name_chs="RLOGIN服务用户认证 失败" name_eng="RLOGIN Service User Authentication Failed" visible="true"/><rule ruleid="40429" enabled="true" group="136315078" action=" db  screen " name="利用MyPHPLinks index.php脚本漏洞绕过验证访问" name_chs="利用MyPHPLinks index.php脚本漏洞绕过验证访问" name_eng="Authentication Bypass via MyPHPLinks index.php Script Vulnerability" visible="true"/><rule ruleid="40428" enabled="true" group="73401423" action=" db  screen " name="Windows系统下iraq_oil蠕虫活动" name_chs="Windows系统下iraq_oil蠕虫活动" name_eng="Worm iraq_oil on Windows" visible="true"/><rule ruleid="20278" enabled="true" group="139460907" action=" db  screen " name="Qualcomm qpopper AUTH命令远程缓冲区溢出攻击" name_chs="Qualcomm qpopper AUTH命令远程缓冲区溢出攻击" name_eng="Qualcomm qpopper AUTH Command Remote Buffer Overflow" visible="true"/><rule ruleid="50066" enabled="true" group="154206298" action=" db  screen " name="RLOGIN服务信任用户认证" name_chs="RLOGIN服务信任用户认证" name_eng="RLOGIN Service Trusting User Authentication" visible="true"/><rule ruleid="50067" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问默认共享C$" name_chs="Windows SMB访问默认共享C$" name_eng="Windows SMB Accessing the Default Share C$" visible="true" merge="[t7200,si,di]"/><rule ruleid="50064" enabled="true" group="233898074" action=" db  screen " name="Oracle数据库远程执行命令操作" name_chs="Oracle数据库远程执行命令操作" name_eng="Oracle Database Remote Command Execution" visible="true"/><rule ruleid="50065" enabled="false" group="95486045" action=" db  screen " name="Windows NBTSTAT信息探测" name_chs="Windows NBTSTAT信息探测" name_eng="Windows NBTSTAT Information Detection" visible="true" merge="[t86400,si]"/><rule ruleid="50062" enabled="true" group="95682639" action=" db  screen " name="Windows系统Worm.SoBig蠕虫病毒利用共享传播" name_chs="Windows系统Worm.SoBig蠕虫病毒利用共享传播" name_eng="Windows Worm.SoBig Propagation Through Sharing" visible="true"/><rule ruleid="50063" enabled="true" group="95486030" action=" db  screen " name="Windows系统下可疑蠕虫病毒通过共享传播" name_chs="Windows系统下可疑蠕虫病毒通过共享传播" name_eng="Windows Suspicious Worms Propagation Through Sharing" visible="true" merge="[t7200,si]"/><rule ruleid="50060" enabled="true" group="72613967" action=" db  screen " name="POP3服务接收Worm.MiMail蠕虫病毒邮件" name_chs="POP3服务接收Worm.MiMail蠕虫病毒邮件" name_eng="POP3 Service Sending Mails with Worm.MiMail" visible="true"/><rule ruleid="50061" enabled="true" group="72613967" action=" db  screen " name="POP3服务接收Worm.SoBig蠕虫病毒邮件" name_chs="POP3服务接收Worm.SoBig蠕虫病毒邮件" name_eng="POP3 Service Receiving Mails with Worm.SoBig" visible="true"/><rule ruleid="40095" enabled="true" group="138444893" action=" db  screen " name="TELNET服务客户端解析服务器配置" name_chs="TELNET服务客户端解析服务器配置" name_eng="TELNET Service Client Parsing Server Configuration" visible="true"/><rule ruleid="50068" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问默认共享D$" name_chs="Windows SMB访问默认共享D$" name_eng="Windows SMB Accessing the Default Share D$" visible="true" merge="[t7200,si,di]"/><rule ruleid="50069" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问默认共享ADMIN$" name_chs="Windows SMB访问默认共享ADMIN$" name_eng="Windows SMB Accessing the Default Share ADMIN$" visible="true" merge="[t7200,si,di]"/><rule ruleid="20379" enabled="true" group="69206319" action=" db  screen " name="Windows Media服务nsiislog.dll远程缓冲区溢出攻击" name_chs="Windows Media服务nsiislog.dll远程缓冲区溢出攻击" name_eng="Windows Media Service nsiislog.dll Remote Buffer Overflow" visible="true"/><rule ruleid="40769" enabled="true" group="368054347" action=" db  screen " name="SyGate未公开远程管理端口通信" name_chs="SyGate未公开远程管理端口通信" name_eng="SyGate Inpublic Remote Management Port Communication" visible="true"/><rule ruleid="20722" enabled="true" group="203423915" action=" db  screen " name="phpMyDirectory ROOT_PATH参数远程文件包含攻击" name_chs="phpMyDirectory ROOT_PATH参数远程文件包含攻击" name_eng="phpMyDirectory ROOT_PATH Parameter Remote File Inclusion" visible="true"/><rule ruleid="20723" enabled="true" group="203423915" action=" db  screen " name="ScozNet ScozNews CONFIG[main_path]参数远程文件包含攻击" name_chs="ScozNet ScozNews CONFIG[main_path]参数远程文件包含攻击" name_eng="ScozNet ScozNews CONFIG[main_path] Parameter Remote File Inclusion" visible="true"/><rule ruleid="20720" enabled="true" group="203423915" action=" db  screen " name="TR Newsportal poll.php远程文件包含攻击" name_chs="TR Newsportal poll.php远程文件包含攻击" name_eng="TR Newsportal poll.php Remote File Inclusion" visible="true"/><rule ruleid="20721" enabled="true" group="203423915" action=" db  screen " name="phpBazar classified_right.php远程文件包含攻击" name_chs="phpBazar classified_right.php远程文件包含攻击" name_eng="phpBazar classified_right.php Remote File Inclusion" visible="true"/><rule ruleid="20726" enabled="true" group="203423915" action=" db  screen " name="paFileDB pafiledb_constants.php远程文件包含攻击" name_chs="paFileDB pafiledb_constants.php远程文件包含攻击" name_eng="paFileDB pafiledb_constants.php Remote File Inclusion" visible="true"/><rule ruleid="20895" enabled="true" group="68157738" action=" db  screen " name="Ask Toolbar ToolbarSettings ActiveX控件远程栈溢出攻击" name_chs="Ask Toolbar ToolbarSettings ActiveX控件远程栈溢出攻击" name_eng="Ask Toolbar ToolbarSettings ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="20896" enabled="true" group="68157738" action=" db  screen " name="迅雷ActiveX控件DownURL2方式远程缓冲区溢出攻击" name_chs="迅雷ActiveX控件DownURL2方式远程缓冲区溢出攻击" name_eng="Xunlei ActiveX Control DownURL2 Method Remote Buffer Overflow" visible="true"/><rule ruleid="20725" enabled="true" group="203423915" action=" db  screen " name="Squirrelcart cart_content.php远程文件包含攻击" name_chs="Squirrelcart cart_content.php远程文件包含攻击" name_eng="Squirrelcart cart_content.php Remote File Inclusion" visible="true"/><rule ruleid="20898" enabled="true" group="68157738" action=" db  screen " name="雅虎通YVerInfo.dll ActiveX控件远程栈缓冲区溢出攻击" name_chs="雅虎通YVerInfo.dll ActiveX控件远程栈缓冲区溢出攻击" name_eng="Yahoo! Messenger YVerInfo.dll ActiveX Control Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20899" enabled="true" group="68159530" action=" db  screen " name="Macrovision InstallShield Update Service ActiveX非授权下载执行任意程序攻击" name_chs="Macrovision InstallShield Update Service ActiveX非授权下载执行任意程序攻击" name_eng="Macrovision InstallShield Update Service ActiveX Unauthorized Arbitrary Program Execution" visible="true"/><rule ruleid="20728" enabled="true" group="83886383" action=" db  screen " name="Windows RPC DCOM接口UDP长路径名远程堆缓冲区溢出攻击" name_chs="Windows RPC DCOM接口UDP长路径名远程堆缓冲区溢出攻击" name_eng="Windows RPC DCOM Interface UDP Long Path Name Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20729" enabled="true" group="71303467" action=" db  screen " name="InterAccess TelnetD Server远程缓冲区溢出攻击" name_chs="InterAccess TelnetD Server远程缓冲区溢出攻击" name_eng="InterAccess TelnetD Server Remote Buffer Overflow" visible="true"/><rule ruleid="30502" enabled="true" group="203423929" action=" db  screen " name="利用HP Web Jetadmin CGI脚本漏洞及配置文件获取信息" name_chs="利用HP Web Jetadmin CGI脚本漏洞及配置文件获取信息" name_eng="Information Disclosure via HP Web Jetadmin CGI Script Vulnerability and Configuration Files" visible="true"/><rule ruleid="30501" enabled="true" group="136323130" action=" db  screen " name="psinclude.cgi脚本漏洞扫描探测" name_chs="psinclude.cgi脚本漏洞扫描探测" name_eng="psinclude.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="70002" enabled="true" group="233832751" action=" db  screen " name="协议数据溢出SHELLCODE攻击" name_chs="协议数据溢出SHELLCODE攻击" name_eng="Protocol Data Buffer Overflow SHELLCODE Attacks" visible="true"/><rule ruleid="70003" enabled="true" group="233898073" action=" db  screen " name="非默认端口上发现已知协议" name_chs="非默认端口上发现已知协议" name_eng="Known Protocol on Non-default Port" visible="true" merge="[t86400,di]"/><rule ruleid="70001" enabled="true" group="233832783" action=" db  screen " name="协议命令参数超长" name_chs="协议命令参数超长" name_eng="Over-long Protocol Command Argument" visible="true" merge="[t3600]"/><rule ruleid="70004" enabled="false" group="233898073" action=" db  screen " name="发现异常的HTTP协议" name_chs="发现异常的HTTP协议" name_eng="Abnormal HTTP Protocol" visible="false"/><rule ruleid="30507" enabled="true" group="203431998" action=" db  screen " name="漏洞扫描器Nessus扫描探测CGI漏洞" name_chs="漏洞扫描器Nessus扫描探测CGI漏洞" name_eng="Nessus Scanner CGI Vulnerability Detection" visible="true"/><rule ruleid="30506" enabled="true" group="162531390" action=" db  screen  drop " name="Samba远程畸形路径名导致目录遍历攻击" name_chs="Samba远程畸形路径名导致目录遍历攻击" name_eng="Samba Remote Malformed Path Name Directory Traversal" visible="true"/><rule ruleid="40766" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht客户端确认通信" name_chs="DDOS工具Stacheldraht客户端确认通信" name_eng="DDOS Stacheldraht Client Communication Confirmation" visible="true"/><rule ruleid="40767" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht主控端向分布端发送指令" name_chs="DDOS工具Stacheldraht主控端向分布端发送指令" name_eng="DDOS Tool Stacheldraht Console Sending Command to Distributed End" visible="true"/><rule ruleid="10169" enabled="true" group="294651930" action=" db  screen " name="SNMPv3畸形报文处理拒绝服务攻击" name_chs="SNMPv3畸形报文处理拒绝服务攻击" name_eng="SNMPv3 Malformed Message Handling Denial of Service" visible="true"/><rule ruleid="10168" enabled="true" group="300943386" action=" db  screen " name="Cisco IP Phone畸形SIP协议请求拒绝服务攻击" name_chs="Cisco IP Phone畸形SIP协议请求拒绝服务攻击" name_eng="Cisco IP Phone Malformed SIP Protocol Request Denial of Service" visible="true"/><rule ruleid="10167" enabled="true" group="160434202" action=" db  screen " name="GNU Radius SNMP字符串长度整数溢出拒绝服务攻击" name_chs="GNU Radius SNMP字符串长度整数溢出拒绝服务攻击" name_eng="GNU Radius SNMP String Length Integer Overflow Denial of Service" visible="true"/><rule ruleid="10166" enabled="true" group="69208090" action=" db  screen " name="Apache Tomcat MS-DOS设备名远程拒绝服务攻击" name_chs="Apache Tomcat MS-DOS设备名远程拒绝服务攻击" name_eng="Apache Tomcat MS-DOS Device Name Remote Denial of Service" visible="true"/><rule ruleid="10165" enabled="true" group="294651930" action=" db  screen " name="Cisco IOS畸形SNMP消息处理远程拒绝服务攻击" name_chs="Cisco IOS畸形SNMP消息处理远程拒绝服务攻击" name_eng="Cisco IOS Malformed SNMP Message Handling Remote Denial of Service" visible="true"/><rule ruleid="10164" enabled="true" group="202377242" action=" db  screen " name="HTTP请求负值Content-Length字段远程拒绝服务攻击" name_chs="HTTP请求负值Content-Length字段远程拒绝服务攻击" name_eng="HTTP Request Negative Content-Length Field Remote Denial of Service" visible="true"/><rule ruleid="20094" enabled="true" group="136315051" action=" db  screen  drop " name="利用WebGlimpse aglimpse脚本漏洞" name_chs="利用WebGlimpse aglimpse脚本漏洞" name_eng="WebGlimpse aglimpse Script Vulnerability" visible="true"/><rule ruleid="10162" enabled="true" group="68159514" action=" db  screen " name="Mbedthis Software AppWeb HTTP Server设备名访问拒绝服务攻击" name_chs="Mbedthis Software AppWeb HTTP Server设备名访问拒绝服务攻击" name_eng="Mbedthis Software AppWeb HTTP Server Device Name Denial of Service" visible="true"/><rule ruleid="10161" enabled="true" group="68159510" action=" db  screen " name="Jeuce Personal Web Server远程拒绝服务攻击" name_chs="Jeuce Personal Web Server远程拒绝服务攻击" name_eng="Jeuce Personal Web Server Remote Denial of Service" visible="true"/><rule ruleid="10160" enabled="true" group="69206170" action=" db  screen " name="Apple QuickTime/Darwin流服务器MS-DOS设备文件名拒绝服务攻击" name_chs="Apple QuickTime/Darwin流服务器MS-DOS设备文件名拒绝服务攻击" name_eng="Apple QuickTime/Darwin Streaming Server MS-DOS Device Filename Denial of Service" visible="true"/><rule ruleid="40309" enabled="true" group="83894326" action=" db  screen " name="Solaris rpc.rwalld服务存在性UDP扫描探测" name_chs="Solaris rpc.rwalld服务存在性UDP扫描探测" name_eng="Solaris rpc.rwalld Service UDP Detection" visible="true"/><rule ruleid="20658" enabled="true" group="136315051" action=" db  screen " name="YACS远程文件包含攻击" name_chs="YACS远程文件包含攻击" name_eng="YACS Remote File Inclusion" visible="true"/><rule ruleid="20659" enabled="true" group="69206186" action=" db  screen " name="Business Objects Crystal Reports Web表单查看器目录遍历攻击" name_chs="Business Objects Crystal Reports Web表单查看器目录遍历攻击" name_eng="Business Objects Crystal Reports Web Form Viewer Directory Traversal" visible="true"/><rule ruleid="20656" enabled="true" group="203423915" action=" db  screen " name="phpECard远程文件包含攻击" name_chs="phpECard远程文件包含攻击" name_eng="phpECard Remote File Inclusion" visible="true"/><rule ruleid="20657" enabled="true" group="136315051" action=" db  screen " name="FlashChat远程文件包含攻击" name_chs="FlashChat远程文件包含攻击" name_eng="FlashChat Remote File Inclusion" visible="true"/><rule ruleid="20654" enabled="true" group="99615019" action=" db  screen " name="eIQnetworks ESA  LICMGR_ADDLICENSE命令远程缓冲区溢出攻击" name_chs="eIQnetworks ESA  LICMGR_ADDLICENSE命令远程缓冲区溢出攻击" name_eng="eIQnetworks ESA  LICMGR_ADDLICENSE Command Remote Buffer Overflow" visible="true"/><rule ruleid="20655" enabled="true" group="89129259" action=" db  screen " name="NIPrint LPD打印服务程序远程缓冲区溢出攻击" name_chs="NIPrint LPD打印服务程序远程缓冲区溢出攻击" name_eng="NIPrint LPD Spooler Remote Buffer Overflow" visible="true"/><rule ruleid="20653" enabled="true" group="203423915" action=" db  screen " name="phpCoin远程文件包含攻击" name_chs="phpCoin远程文件包含攻击" name_eng="phpCoin Remote File Inclusion" visible="true"/><rule ruleid="20650" enabled="true" group="68157739" action=" db  screen " name="Apache mod_rewrite模块单字节缓冲区溢出攻击" name_chs="Apache mod_rewrite模块单字节缓冲区溢出攻击" name_eng="Apache mod_rewrite Module Off-by-one Buffer Overflow" visible="true"/><rule ruleid="20651" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows Server服务远程缓冲区溢出攻击" name_chs="Microsoft Windows Server服务远程缓冲区溢出攻击" name_eng="Microsoft Windows Server Service Remote Buffer Overflow" visible="true"/><rule ruleid="20384" enabled="true" group="95420975" action=" db  screen " name="Windows SMB暴力猜测用户口令" name_chs="Windows SMB暴力猜测用户口令" name_eng="Windows SMB User Password Brute Force" visible="true"/><rule ruleid="20385" enabled="true" group="99876907" action=" db  screen " name="Windows系统下W32.HLLW.Lovgate蠕虫病毒后门访问" name_chs="Windows系统下W32.HLLW.Lovgate蠕虫病毒后门访问" name_eng="Windows W32.HLLW.Lovgate Backdoor" visible="true"/><rule ruleid="20387" enabled="true" group="136315051" action=" db  screen " name="利用VisualShapers EZContents module.php脚本漏洞远程执行命令" name_chs="利用VisualShapers EZContents module.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via VisualShapers EZContents module.php Script Vulnerability" visible="true"/><rule ruleid="20380" enabled="true" group="233832751" action=" db  screen  drop " name="Real Networks Helix Universal Server RTSP URI处理远程缓冲区溢出攻击" name_chs="Real Networks Helix Universal Server RTSP URI处理远程缓冲区溢出攻击" name_eng="Real Networks Helix Universal Server RTSP URI Processing Remote Buffer Overflow" visible="true"/><rule ruleid="20381" enabled="true" group="202375726" action=" db  screen " name="HTTP服务暴力猜测口令攻击" name_chs="HTTP服务暴力猜测口令攻击" name_eng="HTTP Service Brute-force" visible="true" merge="[t7200,di]"/><rule ruleid="20382" enabled="true" group="99615023" action=" db  screen " name="Microsoft Windows工作站服务远程缓冲区溢出攻击" name_chs="Microsoft Windows工作站服务远程缓冲区溢出攻击" name_eng="Microsoft Windows Workstation Service Remote Buffer Overflow" visible="true"/><rule ruleid="20383" enabled="true" group="69206315" action=" db  screen " name="Microsoft FrontPage POST请求远程缓冲区溢出攻击" name_chs="Microsoft FrontPage POST请求远程缓冲区溢出攻击" name_eng="Microsoft FrontPage POST Request Remote Buffer Overflow" visible="true"/><rule ruleid="20388" enabled="true" group="136315055" action=" db  screen " name="利用PHPDig config.php脚本漏洞远程执行命令" name_chs="利用PHPDig config.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via PHPDig config.php Script Vulnerability" visible="true"/><rule ruleid="20389" enabled="true" group="70254895" action=" db  screen  drop " name="Serv-U FTP服务器SITE CHMOD命令超长文件名远程溢出攻击" name_chs="Serv-U FTP服务器SITE CHMOD命令超长文件名远程溢出攻击" name_eng="Serv-U FTP Server SITE CHMOD Command Over-long Filename Remote Buffer Overflow" visible="true"/><rule ruleid="20478" enabled="true" group="203423919" action=" db  screen " name="PHPKIT CGI脚本SQL注入攻击" name_chs="PHPKIT CGI脚本SQL注入攻击" name_eng="PHPKIT CGI Script SQL Injection" visible="true"/><rule ruleid="20479" enabled="true" group="99615019" action=" db  screen  drop " name="CA BrightStor ARCserve/Enterprise发现服务SERVICEPC远程溢出攻击" name_chs="CA BrightStor ARCserve/Enterprise发现服务SERVICEPC远程溢出攻击" name_eng="CA BrightStor ARCserve/Enterprise Discovery Service SERVICEPC Remote Buffer Overflow" visible="true"/><rule ruleid="20472" enabled="true" group="99616811" action=" db  screen " name="Microsoft WINS内存覆盖任意指令执行攻击" name_chs="Microsoft WINS内存覆盖任意指令执行攻击" name_eng="Microsoft WINS Memory Overwriting Arbitrary Code Execution" visible="true"/><rule ruleid="20473" enabled="true" group="99615019" action=" db  screen " name="Microsoft WINS服务畸形包远程缓冲区溢出攻击" name_chs="Microsoft WINS服务畸形包远程缓冲区溢出攻击" name_eng="Microsoft WINS Service Malformed Packet Remote Buffer Overflow" visible="true"/><rule ruleid="20470" enabled="true" group="203424047" action=" db  screen " name="Microsoft Windows GDI+ JPG解析组件缓冲区溢出攻击" name_chs="Microsoft Windows GDI+ JPG解析组件缓冲区溢出攻击" name_eng="Microsoft Windows GDI+ JPG Resolution Buffer Overflow" visible="true"/><rule ruleid="20471" enabled="true" group="204472623" action=" db  screen " name="WS_FTP Server命令参数处理缓冲区溢出攻击" name_chs="WS_FTP Server命令参数处理缓冲区溢出攻击" name_eng="WS_FTP Server Command Parameter Handling Buffer Overflow" visible="true"/><rule ruleid="20476" enabled="true" group="69206187" action=" db  screen " name="Windows NT IIS MSDAC RDS远程执行命令攻击" name_chs="Windows NT IIS MSDAC RDS远程执行命令攻击" name_eng="Windows NT IIS MSDAC RDS Remote Code Execution" visible="true"/><rule ruleid="20477" enabled="true" group="203423919" action=" db  screen " name="利用AwStats CGI脚本远程执行命令攻击" name_chs="利用AwStats CGI脚本远程执行命令攻击" name_eng="Remomte Code Execution via AwStats CGI Script" visible="true"/><rule ruleid="20474" enabled="true" group="203423915" action=" db  screen " name="Ikonboard ikonboard.cgi远程SQL注入攻击" name_chs="Ikonboard ikonboard.cgi远程SQL注入攻击" name_eng="Ikonboard ikonboard.cgi Remote SQL Injection" visible="true"/><rule ruleid="20475" enabled="true" group="203423915" action=" db  screen " name="利用Zeroboard多个CGI脚本远程执行命令攻击" name_chs="利用Zeroboard多个CGI脚本远程执行命令攻击" name_eng="Zeroboard multiple CGI Scripts Remomte Code Execution" visible="true"/><rule ruleid="30293" enabled="true" group="136323129" action=" db  screen " name="Phorum系列脚本漏洞扫描探测" name_chs="Phorum系列脚本漏洞扫描探测" name_eng="PhorumSeries Script Vulnerability Detection" visible="true"/><rule ruleid="30439" enabled="true" group="136323130" action=" db  screen " name="upload.cgi脚本漏洞扫描探测" name_chs="upload.cgi脚本漏洞扫描探测" name_eng="upload.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30438" enabled="true" group="203431994" action=" db  screen " name="Webchat defines.php脚本漏洞扫描探测" name_chs="Webchat defines.php脚本漏洞扫描探测" name_eng="Webchat defines.php Script Vulnerability Detection" visible="true"/><rule ruleid="30437" enabled="true" group="136323126" action=" db  screen " name="phping脚本漏洞扫描探测" name_chs="phping脚本漏洞扫描探测" name_eng="phping Script Vulnerability Detection" visible="true"/><rule ruleid="30435" enabled="true" group="203431994" action=" db  screen " name="通过Web服务访问password.txt文件获取数据信息" name_chs="通过Web服务访问password.txt文件获取数据信息" name_eng="Data Disclosure from password.txt via Web Service" visible="true"/><rule ruleid="30433" enabled="true" group="203431998" action=" db  screen " name="Invision Board ipchat.php脚本漏洞扫描探测" name_chs="Invision Board ipchat.php脚本漏洞扫描探测" name_eng="Invision Board ipchat.php Script Vulnerability Detection" visible="true"/><rule ruleid="30432" enabled="true" group="203431994" action=" db  screen " name="IRIX parse_xml.cgi脚本漏洞扫描探测" name_chs="IRIX parse_xml.cgi脚本漏洞扫描探测" name_eng="IRIX parse_xml.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30431" enabled="true" group="203431994" action=" db  screen " name="DotBr system.php3脚本漏洞扫描探测" name_chs="DotBr system.php3脚本漏洞扫描探测" name_eng="DotBr system.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="30430" enabled="true" group="203431994" action=" db  screen " name="DotBr exec.php3脚本漏洞扫描探测" name_chs="DotBr exec.php3脚本漏洞扫描探测" name_eng="DotBr exec.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="40785" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE JavaScript OnLoad处理器畸形代码邮件引用" name_chs="Microsoft IE JavaScript OnLoad处理器畸形代码邮件引用" name_eng="Microsoft IE JavaScript OnLoad Processor Vulnerability Mail" visible="true"/><rule ruleid="30297" enabled="true" group="136323130" action=" db  screen " name="vpopmail-CGIApps vadddomain脚本漏洞扫描探测" name_chs="vpopmail-CGIApps vadddomain脚本漏洞扫描探测" name_eng="vpopmail-CGIApps vadddomain Script Vulnerability Detection" visible="true"/><rule ruleid="30296" enabled="true" group="78645306" action=" db  screen " name="SolarWinds TFTP服务程序目录遍历攻击" name_chs="SolarWinds TFTP服务程序目录遍历攻击" name_eng="SolarWinds TFTP Server Directory Traversal" visible="true"/><rule ruleid="30187" enabled="true" group="136323126" action=" db  screen " name="Amaya sendtemp.pl脚本漏洞扫描探测" name_chs="Amaya sendtemp.pl脚本漏洞扫描探测" name_eng="Amaya sendtemp.pl Script Vulnerability Detection" visible="true"/><rule ruleid="10141" enabled="true" group="233834522" action=" db  screen " name="IBM DB2 Discovery服务UDP远程拒绝服务攻击" name_chs="IBM DB2 Discovery服务UDP远程拒绝服务攻击" name_eng="IBM DB2 Discovery Service UDP Remote Denial of Service" visible="true"/><rule ruleid="30185" enabled="true" group="203431994" action=" db  screen " name="EZShopper loadpage.cgi脚本漏洞扫描探测" name_chs="EZShopper loadpage.cgi脚本漏洞扫描探测" name_eng="EZShopper loadpage.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30184" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/anot3.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/anot3.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/anot3.htr File" visible="true"/><rule ruleid="30183" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/anot.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/anot.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/anot.htr File" visible="true"/><rule ruleid="30182" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp4b.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp4b.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp4b.htr File" visible="true"/><rule ruleid="30181" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp4.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp4.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp4.htr File" visible="true"/><rule ruleid="10140" enabled="true" group="203425818" action=" db  screen " name="Oracle9iAS Web Cache远程拒绝服务攻击" name_chs="Oracle9iAS Web Cache远程拒绝服务攻击" name_eng="Oracle9iAS Web Cache Remote Denial of Service" visible="true"/><rule ruleid="30294" enabled="true" group="203423926" action=" db  screen " name="myPHPNuke phptonuke.php脚本漏洞扫描探测" name_chs="myPHPNuke phptonuke.php脚本漏洞扫描探测" name_eng="myPHPNuke phptonuke.php Script Vulnerability Detection" visible="true"/><rule ruleid="40306" enabled="true" group="337641643" action=" db  screen " name="Cisco IOS Web配置接口绕过安全认证攻击" name_chs="Cisco IOS Web配置接口绕过安全认证攻击" name_eng="Cisco IOS Web Config Interface Authentication Bypass" visible="true"/><rule ruleid="40307" enabled="true" group="153157722" action=" db  screen " name="RSH服务root用户操作" name_chs="RSH服务root用户操作" name_eng="RSH Service root User Operation" visible="true"/><rule ruleid="30189" enabled="true" group="136323130" action=" db  screen " name="CdomainFree whois_raw.cgi脚本漏洞扫描探测" name_chs="CdomainFree whois_raw.cgi脚本漏洞扫描探测" name_eng="CdomainFree whois_raw.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30188" enabled="true" group="136315062" action=" db  screen " name="利用WebSPIRS webspirs.cgi脚本漏洞远程遍历目录" name_chs="利用WebSPIRS webspirs.cgi脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via WebSPIRS webspirs.cgi Script Vulnerability" visible="true"/><rule ruleid="20271" enabled="true" group="70254891" action=" db  screen " name="WS_FTP Server CPWD远程缓冲区溢出攻击" name_chs="WS_FTP Server CPWD远程缓冲区溢出攻击" name_eng="WS_FTP Server CPWD Remote Buffer Overflow" visible="true"/><rule ruleid="20273" enabled="true" group="137365562" action=" db  screen " name="Solaris FTP畸形CWD命令引发CoreDump攻击" name_chs="Solaris FTP畸形CWD命令引发CoreDump攻击" name_eng="Solaris FTP Malformed CWD Command CoreDump Attack" visible="true"/><rule ruleid="20274" enabled="true" group="88080683" action=" db  screen " name="Microsoft SQL Server/MSDE扩展存储过程xp_displayparamstmt远程缓冲区溢出攻击" name_chs="Microsoft SQL Server/MSDE扩展存储过程xp_displayparamstmt远程缓冲区溢出攻击" name_eng="Microsoft SQL Server/MSDE Exteneded Stored Procedure xp_displayparamstmt Remote Buffer Overflow" visible="true"/><rule ruleid="20275" enabled="true" group="88080683" action=" db  screen " name="Microsoft SQL Server/MSDE扩展存储过程xp_setsqlsecurity远程缓冲区溢出攻击" name_chs="Microsoft SQL Server/MSDE扩展存储过程xp_setsqlsecurity远程缓冲区溢出攻击" name_eng="Microsoft SQL Server/MSDE Extended Stored Procedure xp_setsqlsecurity Remote Buffer Overflow" visible="true"/><rule ruleid="20276" enabled="true" group="88080687" action=" db  screen " name="Microsoft SQL Server RAISERROR语句缓冲区溢出攻击" name_chs="Microsoft SQL Server RAISERROR语句缓冲区溢出攻击" name_eng="Microsoft SQL Server RAISERROR Statement Buffer Overflow" visible="true"/><rule ruleid="40092" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Prosiak木马建立连接" name_chs="Windows系统下Prosiak木马建立连接" name_eng="Trojan Prosiak Connection on Windows" visible="true"/><rule ruleid="10145" enabled="true" group="272631834" action=" db  screen " name="Cisco IOS TELNET环境变量处理拒绝服务攻击" name_chs="Cisco IOS TELNET环境变量处理拒绝服务攻击" name_eng="Cisco IOS TELNET Environment Variable Handling Denial of Service" visible="true"/><rule ruleid="10144" enabled="true" group="275777562" action=" db  screen " name="Cisco VPN 3000系列畸形SSH初始化包拒绝服务攻击" name_chs="Cisco VPN 3000系列畸形SSH初始化包拒绝服务攻击" name_eng="Cisco VPN 3000 Series Malformed SSH Initialization Packet Denial of Service" visible="true"/><rule ruleid="20076" enabled="true" group="136315066" action=" db  screen  drop " name="利用NCSA nph-test-cgi脚本漏洞远程浏览目录" name_chs="利用NCSA nph-test-cgi脚本漏洞远程浏览目录" name_eng="Remote Directory Browsing via NCSA nph-test-cgi Script Vulnerability" visible="true"/><rule ruleid="20075" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.cachefsd远程堆溢出攻击" name_chs="Solaris rpc.cachefsd远程堆溢出攻击" name_eng="Solaris rpc.cachefsd Remote Heap Overflow" visible="true"/><rule ruleid="10180" enabled="true" group="83888154" action=" db  screen " name="Microsoft Windows打印后台程序GetPrinterData过程远程拒绝服务攻击" name_chs="Microsoft Windows打印后台程序GetPrinterData过程远程拒绝服务攻击" name_eng="Microsoft Windows Spooler GetPrinterData Procedure Remote Denial of Service" visible="true"/><rule ruleid="20527" enabled="true" group="83887151" action=" db  screen  drop " name="Windows系统下ZoTob蠕虫利用MS05-039漏洞传播" name_chs="Windows系统下ZoTob蠕虫利用MS05-039漏洞传播" name_eng="Windows ZoTob Propagation via MS05-039 Vulnerability" visible="true"/><rule ruleid="10189" enabled="false" group="99616794" action=" db  screen " name="传奇假人拒绝服务攻击" name_chs="传奇假人拒绝服务攻击" name_eng="Legend Dummy Denial of Service" visible="false"/><rule ruleid="20079" enabled="true" group="136315051" action=" db  screen " name="利用CGISCRIPT.NET csChatRBox.cgi脚本漏洞远程执行命令" name_chs="利用CGISCRIPT.NET csChatRBox.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CGISCRIPT.NET csChatRBox.cgi Script Vulnerability" visible="true"/><rule ruleid="40768" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Infector 1.7木马通信" name_chs="Windows系统下Infector 1.7木马通信" name_eng="Trojan Infector 1.7 Communication on Windows" visible="true"/><rule ruleid="10149" enabled="true" group="300943386" action=" db  screen " name="H.323协议Calling Party Number数据畸形" name_chs="H.323协议Calling Party Number数据畸形" name_eng="H.323 Protocol Calling Party Number Malformed Data" visible="true"/><rule ruleid="30509" enabled="true" group="233840702" action=" db  screen " name="端口扫描器ICMP PING扫描操作" name_chs="端口扫描器ICMP PING扫描操作" name_eng="Port Scanner ICMP PING Scanning" visible="true"/><rule ruleid="30508" enabled="true" group="204480574" action=" db  screen " name="漏洞扫描器Nessus扫描探测FTP漏洞" name_chs="漏洞扫描器Nessus扫描探测FTP漏洞" name_eng="Nessus Scanner Detecting FTP Vulnerability" visible="true"/><rule ruleid="10148" enabled="true" group="300943386" action=" db  screen " name="H.323协议Called Party Number数据畸形" name_chs="H.323协议Called Party Number数据畸形" name_eng="H.323 Protocol Called Party Number Malformed Data" visible="true"/><rule ruleid="40760" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Furax木马通信" name_chs="Windows系统下Furax木马通信" name_eng="Trojan Furax Communication on Windows" visible="true"/><rule ruleid="40761" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下黑星木马通信" name_chs="Windows系统下黑星木马通信" name_eng="Trojan BlackStar Trojan Communnication" visible="true"/><rule ruleid="40762" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Institution2004木马通信" name_chs="Windows系统下Institution2004木马通信" name_eng="Trojan Institution2004 Communication on Windows" visible="true"/><rule ruleid="40763" enabled="true" group="99876939" action=" db  screen " name="Windows系统下威金蠕虫病毒解析恶意网站域名" name_chs="Windows系统下威金蠕虫病毒解析恶意网站域名" name_eng="Worm.Viking Parsing Malicious Website Domain Name on Windows System" visible="true"/><rule ruleid="40764" enabled="true" group="99618887" action=" db  screen " name="Windows系统下流萤 2.5木马通信" name_chs="Windows系统下流萤 2.5木马通信" name_eng="FireFly 2.5 Communication on Windows" visible="true"/><rule ruleid="40765" enabled="true" group="99618890" action=" db  screen  drop " name="Windows系统下自由远程管理系统木马侧通信" name_chs="Windows系统下自由远程管理系统木马侧通信" name_eng="Free Remote Management System Communication on Windows" visible="true"/><rule ruleid="30505" enabled="true" group="136315070" action=" db  screen " name="利用Turbo Seek tseekdir.cgi脚本漏洞读取文件" name_chs="利用Turbo Seek tseekdir.cgi脚本漏洞读取文件" name_eng="File Reading via Turbo Seek tseekdir.cgi Script Vulnerability" visible="true"/><rule ruleid="30504" enabled="true" group="163610685" action=" db  screen " name="CVS未文档化命令获取信息攻击" name_chs="CVS未文档化命令获取信息攻击" name_eng="CVS Undocument Command Information Disclosure" visible="true"/><rule ruleid="40540" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Meet The Lamer木马通信" name_chs="Windows系统下Meet The Lamer木马通信" name_eng="Trojan Meet The Lamer Communication on Windows" visible="true"/><rule ruleid="40541" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Michal木马通信" name_chs="Windows系统下Michal木马通信" name_eng="Trojan Michal Communication on Windows" visible="true"/><rule ruleid="40542" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Microspy木马通信" name_chs="Windows系统下Microspy木马通信" name_eng="Trojan Microspy Communication on Windows" visible="true"/><rule ruleid="40543" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Millenium木马通信" name_chs="Windows系统下Millenium木马通信" name_eng="Trojan Millenium Communication on Windows" visible="true"/><rule ruleid="40544" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mini Oblivion木马通信" name_chs="Windows系统下Mini Oblivion木马通信" name_eng="Trojan Mini Oblivion Communication on Windows" visible="true"/><rule ruleid="40545" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mneah Trojan木马通信" name_chs="Windows系统下Mneah Trojan木马通信" name_eng="Trojan Mneah Trojan Communication on Windows" visible="true"/><rule ruleid="40546" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下MoonPie木马通信" name_chs="Windows系统下MoonPie木马通信" name_eng="Trojan MoonPie Communication on Windows" visible="true"/><rule ruleid="40547" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mosucker木马通信" name_chs="Windows系统下Mosucker木马通信" name_eng="Trojan Mosucker Communication on Windows" visible="true"/><rule ruleid="40548" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Administrator木马通信" name_chs="Windows系统下Net Administrator木马通信" name_eng="Trojan Net Administrator Communication on Windows" visible="true"/><rule ruleid="40549" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Net Metropolitan木马通信" name_chs="Windows系统下Net Metropolitan木马通信" name_eng="Trojan Net Metropolitan Communication on Windows" visible="true"/><rule ruleid="40786" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE文件下载对话框控制恶意代码邮件引用" name_chs="Microsoft IE文件下载对话框控制恶意代码邮件引用" name_eng="Microsoft IE File Download Dialog Box Control Mail" visible="true"/><rule ruleid="40787" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE畸形COM对象实例化代码邮件引用" name_chs="Microsoft IE畸形COM对象实例化代码邮件引用" name_eng="Microsoft IE Malformed COM Object Instantiation Vulnerability Mail" visible="true"/><rule ruleid="40784" enabled="true" group="75563082" action=" db  screen " name="Microsoft IE javaprxy.dll COM对象邮件内容引用" name_chs="Microsoft IE javaprxy.dll COM对象邮件内容引用" name_eng="Microsoft IE javaprxy.dll COM Object Vulnerability Mail" visible="true"/><rule ruleid="30290" enabled="true" group="203423926" action=" db  screen " name="mcNews header.php脚本漏洞扫描探测" name_chs="mcNews header.php脚本漏洞扫描探测" name_eng="mcNews header.php Script Vulnerability Detection" visible="true"/><rule ruleid="40782" enabled="true" group="75563082" action=" db  screen " name="Microsoft Word畸形字体文档邮件附件传播" name_chs="Microsoft Word畸形字体文档邮件附件传播" name_eng="Microsoft Word Malformed Font Document Attachment Propagation" visible="true"/><rule ruleid="40783" enabled="true" group="75563082" action=" db  screen " name="Microsoft Outlook Web Access恶意跨站脚本链接邮件传播" name_chs="Microsoft Outlook Web Access恶意跨站脚本链接邮件传播" name_eng="Microsoft Outlook Web Access Malicious Cross Site Scripting Mail Propagation" visible="true"/><rule ruleid="40780" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows资源管理器预览框脚本注入畸形文档邮件附件传播" name_chs="Microsoft Windows资源管理器预览框脚本注入畸形文档邮件附件传播" name_eng="Microsoft Windows Explorer Preview Pane Script Injection Malformed Document Attachment Propagation" visible="true"/><rule ruleid="40781" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows颜色管理模块畸形ICC配置文档邮件附件传播" name_chs="Microsoft Windows颜色管理模块畸形ICC配置文档邮件附件传播" name_eng="Microsoft Windows Color Management Module Malformed ICC Configuration Document Attachment Propagation" visible="true"/><rule ruleid="30299" enabled="true" group="203423930" action=" db  screen " name="利用avatar.php脚本漏洞遍历目录" name_chs="利用avatar.php脚本漏洞遍历目录" name_eng="Directory Traversal via avatar.php Script Vulnerability" visible="true"/><rule ruleid="30298" enabled="true" group="136323125" action=" db  screen " name="Molly系列脚本漏洞扫描探测" name_chs="Molly系列脚本漏洞扫描探测" name_eng="Molly Series Script Vulnerability Detection" visible="true"/><rule ruleid="40788" enabled="true" group="75563082" action=" db  screen " name="Microsoft Windows ASN.1库BER解码漏洞SMTP协议攻击" name_chs="Microsoft Windows ASN.1库BER解码漏洞SMTP协议攻击" name_eng="Microsoft Windows ASN.1 Base BER Decoding Vulnerability SMTP Protocol Attack" visible="true"/><rule ruleid="40789" enabled="true" group="75563082" action=" db  screen " name="Microsoft Visual Studio .NET msdds.dll远程代码执行攻击" name_chs="Microsoft Visual Studio .NET msdds.dll远程代码执行攻击" name_eng="Microsoft Visual Studio .NET msdds.dll Remote Code Execution Attack" visible="true"/><rule ruleid="30221" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage配置文件registrations.txt获取服务器信息" name_chs="访问Frontpage配置文件registrations.txt获取服务器信息" name_eng="Server Information Disclosure from Frontpage Config File registrations.txt" visible="true"/><rule ruleid="30341" enabled="true" group="337641654" action=" db  screen " name="Novell GroupWise GWWEB.EXE程序漏洞扫描利用" name_chs="Novell GroupWise GWWEB.EXE程序漏洞扫描利用" name_eng="Novell GroupWise GWWEB.EXE Detection" visible="true"/><rule ruleid="30340" enabled="true" group="70256687" action=" db  screen  drop " name="Serv-U FTP远程目录遍历攻击" name_chs="Serv-U FTP远程目录遍历攻击" name_eng="Serv-U FTP Remote Directory Traversal" visible="true"/><rule ruleid="30343" enabled="true" group="136315062" action=" db  screen " name="apexec.pl脚本漏洞扫描利用" name_chs="apexec.pl脚本漏洞扫描利用" name_eng="apexec.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30345" enabled="true" group="203431993" action=" db  screen " name="Allaire ColdFusion application.cfm脚本漏洞扫描探测" name_chs="Allaire ColdFusion application.cfm脚本漏洞扫描探测" name_eng="Allaire ColdFusion application.cfm Script Vulnerability Detection" visible="true"/><rule ruleid="30344" enabled="true" group="203423929" action=" db  screen " name="Allaire ColdFusion 4.0x cfcache.map脚本漏洞扫描探测" name_chs="Allaire ColdFusion 4.0x cfcache.map脚本漏洞扫描探测" name_eng="Allaire ColdFusion 4.0x cfcache.map Script Vulnerability Detection" visible="true"/><rule ruleid="30347" enabled="true" group="203423926" action=" db  screen " name="Apache::ASP source.asp脚本漏洞扫描探测" name_chs="Apache::ASP source.asp脚本漏洞扫描探测" name_eng="Apache::ASP source.asp Script Vulnerability Detection" visible="true"/><rule ruleid="30349" enabled="true" group="337641654" action=" db  screen " name="NetWare Web Server 2.x convert.bas脚本漏洞扫描利用" name_chs="NetWare Web Server 2.x convert.bas脚本漏洞扫描利用" name_eng="NetWare Web Server 2.x convert.bas Script Vulnerability Detection" visible="true"/><rule ruleid="30348" enabled="true" group="233840702" action=" db  screen " name="端口扫描器Superscan PING操作" name_chs="端口扫描器Superscan PING操作" name_eng="Port Scanner Superscan PING Operation" visible="true"/><rule ruleid="50181" enabled="true" group="68223061" action=" db  screen " name="HTTP协议CONNECT遂道功能连接访问" name_chs="HTTP协议CONNECT遂道功能连接访问" name_eng="HTTP Protocol CONNECT Tunnel Feature Connection Access" visible="true"/><rule ruleid="50180" enabled="true" group="68223066" action=" db  screen " name="网络代理软件http-tunnel数据通信" name_chs="网络代理软件http-tunnel数据通信" name_eng="Network Agent Software http-tunnel Data Communication" visible="true"/><rule ruleid="40438" enabled="true" group="99615819" action=" db  screen  drop " name="Windows系统Nimda蠕虫利用Unicode漏洞传播" name_chs="Windows系统Nimda蠕虫利用Unicode漏洞传播" name_eng="Worm Nimda Propagation on Windows via Unicode Vulnerability" visible="true"/><rule ruleid="50187" enabled="true" group="99680341" action=" db  screen " name="股票行情分析操作软件天一证券用户登录" name_chs="股票行情分析操作软件天一证券用户登录" name_eng="Stock Market Analtsis Software Tianyi Securities User Login" visible="true"/><rule ruleid="50186" enabled="true" group="68288601" action=" db  screen " name="P2P文件共享工具迅雷通过HTTP协议多线程文件下载" name_chs="P2P文件共享工具迅雷通过HTTP协议多线程文件下载" name_eng="P2P File Sharing Tool Xunlei Multi-thread File Downloading Through HTTP Protocol" visible="true"/><rule ruleid="50189" enabled="true" group="68288601" action=" db  screen " name="P2P文件共享工具迅雷通过HTTP协议单线程文件下载" name_chs="P2P文件共享工具迅雷通过HTTP协议单线程文件下载" name_eng="P2P File Sharing Tool Xunlei Single Thread File Downloading Through HTTP Protocol" visible="true"/><rule ruleid="40435" enabled="false" group="99618895" action=" db  screen " name="Remote Administrator远程控制软件建立连接" name_chs="Remote Administrator远程控制软件建立连接" name_eng="Remote Control Software Remote Administrator Connection" visible="true" merge="[t7200,si,di]"/><rule ruleid="40436" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下BackOrifice 2000木马客户端连接服务端" name_chs="Windows系统下BackOrifice 2000木马客户端连接服务端" name_eng="Trojan BackOrifice 2000 Client Connection to Server on Windows" visible="true"/><rule ruleid="40437" enabled="true" group="72352843" action=" db  screen " name="Windows系统下Happy99邮件蠕虫活动" name_chs="Windows系统下Happy99邮件蠕虫活动" name_eng="Happy99 Mail Virus on Windows" visible="true"/><rule ruleid="40430" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下BackOrifice 1.2木马PING操作" name_chs="Windows系统下BackOrifice 1.2木马PING操作" name_eng="Trojan BackOrifice 1.2 PING Operation on Windows" visible="true"/><rule ruleid="40432" enabled="true" group="202440797" action=" db  screen " name="HTTP服务基本登录认证" name_chs="HTTP服务基本登录认证" name_eng="HTTP Service Basic Login Authentication" visible="true" merge="[t7200,di]"/><rule ruleid="50053" enabled="false" group="138477662" action=" db  screen " name="TELNET服务用户弱口令认证" name_chs="TELNET服务用户弱口令认证" name_eng="User Weak Password Authentication in TELNET Service" visible="true"/><rule ruleid="50052" enabled="true" group="205586526" action=" db  screen " name="TELNET服务root用户认证" name_chs="TELNET服务root用户认证" name_eng="TELNET Service root User Authentication" visible="true"/><rule ruleid="50051" enabled="true" group="205586525" action=" db  screen " name="TELNET服务root用户认证" name_chs="TELNET服务root用户认证" name_eng="TELNET Service root User Authentication" visible="true"/><rule ruleid="50050" enabled="true" group="205586526" action=" db  screen " name="TELNET服务用户认证" name_chs="TELNET服务用户认证" name_eng="TELNET Service User Authentication" visible="true"/><rule ruleid="50057" enabled="true" group="95486045" action=" db  screen " name="Windows XP SMB建立连接" name_chs="Windows XP SMB建立连接" name_eng="Windows XP SMB Connection Establishment" visible="true" merge="[t28800,si,di]"/><rule ruleid="50055" enabled="true" group="95486045" action=" db  screen " name="Windows SMB访问系统注册表" name_chs="Windows SMB访问系统注册表" name_eng="Windows SMB Accessing System Registry" visible="true" merge="[t86400,si]"/><rule ruleid="50054" enabled="true" group="138477662" action=" db  screen " name="TELNET服务用户执行su命令" name_chs="TELNET服务用户执行su命令" name_eng="su Command Execution in TELNET Service" visible="true"/><rule ruleid="50059" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Worm.SoBig蠕虫病毒邮件" name_chs="SMTP服务发送Worm.SoBig蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Worm.SoBig" visible="true"/><rule ruleid="50058" enabled="true" group="233898073" action=" db  screen " name="Oracle数据库访问操作" name_chs="Oracle数据库访问操作" name_eng="Oracle Database Access" visible="true"/><rule ruleid="30488" enabled="true" group="69206202" action=" db  screen " name="利用Microsoft IIS bdir.htr脚本漏洞浏览目录" name_chs="利用Microsoft IIS bdir.htr脚本漏洞浏览目录" name_eng="Directory Browsing via Microsoft IIS bdir.htr Script Vulnerability" visible="true"/><rule ruleid="40261" enabled="true" group="69214270" action=" db  screen " name="Microsoft JET adctest.asp脚本漏洞扫描探测" name_chs="Microsoft JET adctest.asp脚本漏洞扫描探测" name_eng="Microsoft JET adctest.asp Script Vulnerability Detection" visible="true"/><rule ruleid="20869" enabled="true" group="68157738" action=" db  screen " name="HTTP协议Cookie字段超长缓冲区溢出攻击" name_chs="HTTP协议Cookie字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long Cookie Field Buffer Overflow" visible="true"/><rule ruleid="20868" enabled="true" group="76546346" action=" db  screen " name="Novell Netmail IMAP服务AUTHENTICATE GSSAPI远程缓冲区溢出攻击" name_chs="Novell Netmail IMAP服务AUTHENTICATE GSSAPI远程缓冲区溢出攻击" name_eng="Novell Netmail IMAP Service AUTHENTICATE GSSAPI Remote Buffer Overflow" visible="true"/><rule ruleid="20719" enabled="true" group="203423915" action=" db  screen " name="Docebo全局变量远程文件包含攻击" name_chs="Docebo全局变量远程文件包含攻击" name_eng="Docebo global Variable Remote File Inclusion" visible="true"/><rule ruleid="20718" enabled="true" group="203423914" action=" db  screen " name="phpCommunityCalendar多个脚本远程SQL注入攻击" name_chs="phpCommunityCalendar多个脚本远程SQL注入攻击" name_eng="phpCommunityCalendar multiple Scripts Remote SQL Injection" visible="true"/><rule ruleid="20717" enabled="true" group="203423915" action=" db  screen " name="Ovidentia多个脚本远程文件包含攻击" name_chs="Ovidentia多个脚本远程文件包含攻击" name_eng="Ovidentia multiple Scripts Remote File Inclusion" visible="true"/><rule ruleid="20716" enabled="true" group="136315179" action=" db  screen " name="iShopCart远程缓冲区溢出攻击" name_chs="iShopCart远程缓冲区溢出攻击" name_eng="iShopCart Remote Buffer Overflow" visible="true"/><rule ruleid="20715" enabled="true" group="203423914" action=" db  screen " name="SaPHPLesson add.php远程SQL注入攻击" name_chs="SaPHPLesson add.php远程SQL注入攻击" name_eng="SaPHPLesson add.php Remote SQL Injection" visible="true"/><rule ruleid="20714" enabled="true" group="203423914" action=" db  screen " name="SelectaPix远程SQL注入攻击" name_chs="SelectaPix远程SQL注入攻击" name_eng="SelectaPix Remote SQL Injection" visible="true"/><rule ruleid="20713" enabled="true" group="203423915" action=" db  screen " name="DeluxeBB多个脚本远程文件包含攻击" name_chs="DeluxeBB多个脚本远程文件包含攻击" name_eng="DeluxeBB multiple Scripts Remote File Inclusion" visible="true"/><rule ruleid="20712" enabled="true" group="203423915" action=" db  screen " name="Bee-hive远程文件包含攻击" name_chs="Bee-hive远程文件包含攻击" name_eng="Bee-hive Remote File Inclusion" visible="true"/><rule ruleid="20711" enabled="true" group="203423915" action=" db  screen " name="MF Piadas admin.php远程文件包含攻击" name_chs="MF Piadas admin.php远程文件包含攻击" name_eng="MF Piadas admin.php Remote File Inclusion" visible="true"/><rule ruleid="20710" enabled="true" group="203423915" action=" db  screen " name="Galleria远程文件包含攻击" name_chs="Galleria远程文件包含攻击" name_eng="Galleria Remote File Inclusion" visible="true"/><rule ruleid="10163" enabled="true" group="68159515" action=" db  screen " name="HTTP协议头超长HOST字段缓冲区溢出攻击" name_chs="HTTP协议头超长HOST字段缓冲区溢出攻击" name_eng="HTTP Protocol Header Over-long HOST Field Buffer Overflow" visible="true"/><rule ruleid="30029" enabled="true" group="233898069" action=" db  screen " name="ICMP子网掩码请求消息" name_chs="ICMP子网掩码请求消息" name_eng="ICMP Netmask Request Message" visible="true"/><rule ruleid="40061" enabled="true" group="166756425" action=" db  screen " name="由内网向外网发起X Window应用连接" name_chs="由内网向外网发起X Window应用连接" name_eng="X Windows Application Connection Initiated from Intranet to External Network" visible="true"/><rule ruleid="10178" enabled="true" group="166725658" action=" db  screen " name="Asterisk SIP响应远程拒绝服务攻击" name_chs="Asterisk SIP响应远程拒绝服务攻击" name_eng="Asterisk SIP Response Remote Denial of Service" visible="true"/><rule ruleid="10179" enabled="true" group="166725658" action=" db  screen " name="Linksys SPA941 \377字符拒绝服务攻击" name_chs="Linksys SPA941 \377字符拒绝服务攻击" name_eng="Linksys SPA941 \377 Character Denial of Service" visible="true"/><rule ruleid="10170" enabled="true" group="69208090" action=" db  screen " name="Sambar Web服务器例子程序远程拒绝服务攻击" name_chs="Sambar Web服务器例子程序远程拒绝服务攻击" name_eng="Sambar Web Server Sample Program Remote Denial of Service" visible="true"/><rule ruleid="10171" enabled="true" group="83888154" action=" db  screen " name="CA BrightStor ARCserve Backup catirpc.exe远程拒绝服务攻击" name_chs="CA BrightStor ARCserve Backup catirpc.exe远程拒绝服务攻击" name_eng="CA BrightStor ARCserve Backup catirpc.exe Remote Denial of Service" visible="true"/><rule ruleid="10172" enabled="true" group="99616794" action=" db  screen " name="CA BrightStor ARCServe BackUp LGServer畸形数据长度拒绝服务攻击" name_chs="CA BrightStor ARCServe BackUp LGServer畸形数据长度拒绝服务攻击" name_eng="CA BrightStor ARCServe BackUp LGServer Malformed Data Length Denial of Service" visible="true"/><rule ruleid="10173" enabled="true" group="99616794" action=" db  screen " name="Microsoft Systems Management Server远程拒绝服务攻击" name_chs="Microsoft Systems Management Server远程拒绝服务攻击" name_eng="Microsoft Systems Management Server Remote Denial of Service" visible="true"/><rule ruleid="10174" enabled="true" group="300943386" action=" db  screen " name="Cisco 7940/7960 Phone SIP INVITE消息远程拒绝服务攻击" name_chs="Cisco 7940/7960 Phone SIP INVITE消息远程拒绝服务攻击" name_eng="Cisco 7940/7960 Phone SIP INVITE Message Remote Denial of Service" visible="true"/><rule ruleid="10175" enabled="true" group="166725658" action=" db  screen " name="Asterisk畸形SIP消息远程拒绝服务攻击" name_chs="Asterisk畸形SIP消息远程拒绝服务攻击" name_eng="Asterisk Malformed SIP Message Remote Denial of Service" visible="true"/><rule ruleid="10176" enabled="true" group="166725658" action=" db  screen " name="Asterisk SIP畸形INVITE消息远程拒绝服务攻击" name_chs="Asterisk SIP畸形INVITE消息远程拒绝服务攻击" name_eng="Asterisk SIP Malformed INVITE Message Remote Denial of Service" visible="true"/><rule ruleid="10177" enabled="true" group="300943386" action=" db  screen " name="Grandstream BudgeTone-200畸形INVITE消息远程拒绝服务攻击" name_chs="Grandstream BudgeTone-200畸形INVITE消息远程拒绝服务攻击" name_eng="Grandstream BudgeTone-200 Malformed INVITE Message Remote Denial of Service" visible="true"/><rule ruleid="20669" enabled="true" group="203423915" action=" db  screen " name="phpSecurePages cfgProgDir变量远程文件包含攻击" name_chs="phpSecurePages cfgProgDir变量远程文件包含攻击" name_eng="phpSecurePages cfgProgDir Variable Remote File Inclusion" visible="true"/><rule ruleid="20668" enabled="true" group="203423915" action=" db  screen " name="Site@School远程文件包含攻击" name_chs="Site@School远程文件包含攻击" name_eng="Site@School Remote File Inclusion" visible="true"/><rule ruleid="20663" enabled="true" group="203423915" action=" db  screen " name="phpBB db.php phpbb_root_path远程文件包含攻击" name_chs="phpBB db.php phpbb_root_path远程文件包含攻击" name_eng="phpBB db.php phpbb_root_path Remote File Inclusion" visible="true"/><rule ruleid="20662" enabled="true" group="203423915" action=" db  screen " name="AWStats awstats.pl多个参数远程执行命令攻击" name_chs="AWStats awstats.pl多个参数远程执行命令攻击" name_eng="AWStats awstats.pl multiple Parameters Remote Code Execution" visible="true"/><rule ruleid="20661" enabled="true" group="203423915" action=" db  screen " name="Vivvo Article Manager远程文件包含攻击" name_chs="Vivvo Article Manager远程文件包含攻击" name_eng="Vivvo Article Manager Remote File Inclusion" visible="true"/><rule ruleid="20660" enabled="true" group="203423915" action=" db  screen " name="Open Bulletin Board远程文件包含攻击" name_chs="Open Bulletin Board远程文件包含攻击" name_eng="Open Bulletin Board Remote File Inclusion" visible="true"/><rule ruleid="20667" enabled="true" group="203423915" action=" db  screen " name="AllMyGuests远程文件包含攻击" name_chs="AllMyGuests远程文件包含攻击" name_eng="AllMyGuests Remote File Inclusion" visible="true"/><rule ruleid="20666" enabled="true" group="203423915" action=" db  screen " name="Claroline claro_init_local.inc.php远程文件包含攻击" name_chs="Claroline claro_init_local.inc.php远程文件包含攻击" name_eng="Claroline claro_init_local.inc.php Remote File Inclusion" visible="true"/><rule ruleid="20665" enabled="true" group="203423915" action=" db  screen " name="PhotoPost PP_PATH远程文件包含攻击" name_chs="PhotoPost PP_PATH远程文件包含攻击" name_eng="PhotoPost PP_PATH Remote File Inclusion" visible="true"/><rule ruleid="20664" enabled="true" group="203423915" action=" db  screen " name="Tagger LE PHP代码注入执行攻击" name_chs="Tagger LE PHP代码注入执行攻击" name_eng="Tagger LE PHP Code Injection" visible="true"/><rule ruleid="20556" enabled="true" group="136315047" action=" db  screen  drop " name="HP OpenView网络节点管理器远程命令执行攻击" name_chs="HP OpenView网络节点管理器远程命令执行攻击" name_eng="HP OpenView Network Node Manager Remote Command Execution" visible="true"/><rule ruleid="20551" enabled="true" group="203423915" action=" db  screen " name="Mambo globals.php远程文件包含攻击" name_chs="Mambo globals.php远程文件包含攻击" name_eng="Mambo globals.php Remote File Inclusion" visible="true"/><rule ruleid="70100" enabled="true" group="95420975" action="" name="Windows SMB Openuser操作" name_chs="Windows SMB Openuser操作" name_eng="Windows SMB Openuser Operation " visible="false"/><rule ruleid="20550" enabled="true" group="203423919" action=" db  screen " name="PHP-Nuke query功能SQL注入攻击" name_chs="PHP-Nuke query功能SQL注入攻击" name_eng="PHP-Nuke query function SQL Injection" visible="true"/><rule ruleid="20447" enabled="true" group="203423915" action=" db  screen " name="利用Mambo Server Function.php脚本漏洞远程执行命令" name_chs="利用Mambo Server Function.php脚本漏洞远程执行命令" name_eng="Remote Command Execution via Mambo Server Function.php Script Vulnerability" visible="true"/><rule ruleid="20914" enabled="true" group="68157738" action=" db  screen " name="VLC媒体播放器axvlc.dll ActiveX控件内存破坏攻击" name_chs="VLC媒体播放器axvlc.dll ActiveX控件内存破坏攻击" name_eng="VLC Media Player axvlc.dll ActiveX Control Memory Corruption" visible="true"/><rule ruleid="20917" enabled="true" group="95420714" action=" db  screen " name="Cisco Security Agent for Windows SMB报文远程栈溢出攻击" name_chs="Cisco Security Agent for Windows SMB报文远程栈溢出攻击" name_eng="Cisco Security Agent for Windows SMB Packet Remote Stack Overflow" visible="true"/><rule ruleid="20444" enabled="true" group="203423919" action=" db  screen " name="利用YaPiG add_comment.php脚本漏洞远程执行命令" name_chs="利用YaPiG add_comment.php脚本漏洞远程执行命令" name_eng="Remote Command Execution via YaPiG add_comment.php Script Vulnerability" visible="true"/><rule ruleid="20443" enabled="true" group="203423915" action=" db  screen " name="利用Gallery save_photos.php脚本漏洞远程执行命令" name_chs="利用Gallery save_photos.php脚本漏洞远程执行命令" name_eng="Remote Command Execution via Gallery save_photos.php Script Vulnerability" visible="true"/><rule ruleid="20910" enabled="true" group="68159530" action=" db  screen " name="Microsoft IE FirefoxURL协议处理器命令注入攻击" name_chs="Microsoft IE FirefoxURL协议处理器命令注入攻击" name_eng="Microsoft IE FirefoxURL Protocol Handler Command Injection" visible="true"/><rule ruleid="20441" enabled="true" group="136315051" action=" db  screen " name="利用CVSTrac filediff CGI程序漏洞远程执行命令" name_chs="利用CVSTrac filediff CGI程序漏洞远程执行命令" name_eng="Remote Command Execution via CVSTrac filediff CGI Program Vulnerability" visible="true"/><rule ruleid="20912" enabled="true" group="99615018" action=" db  screen " name="X.Org X字体服务器内存破坏攻击" name_chs="X.Org X字体服务器内存破坏攻击" name_eng="X.Org X Font Server Memory Corruption" visible="true"/><rule ruleid="20919" enabled="true" group="68159530" action=" db  screen " name="HP信息中心HPInfoDLL.dll ActiveX控件远程代码执行攻击" name_chs="HP信息中心HPInfoDLL.dll ActiveX控件远程代码执行攻击" name_eng="HP Information Center HPInfoDLL.dll ActiveX Control Remote Code Execution" visible="true"/><rule ruleid="20918" enabled="true" group="83886378" action=" db  screen " name="Microsoft消息队列服务栈溢出攻击（MS07-065)" name_chs="Microsoft消息队列服务栈溢出攻击（MS07-065)" name_eng="Microsoft Message Queue Service Stack Overflow Vulnerability" visible="true"/><rule ruleid="20449" enabled="true" group="142639143" action=" db  screen  drop " name="Sendmail WIZ命令远程执行命令攻击" name_chs="Sendmail WIZ命令远程执行命令攻击" name_eng="Sendmail WIZ Remote Command Execution" visible="true"/><rule ruleid="20448" enabled="true" group="99615019" action=" db  screen  drop " name="Icecast多个头结构字段远程溢出攻击" name_chs="Icecast多个头结构字段远程溢出攻击" name_eng="Icecast Multiple Head Structure Fields Remote Buffer Overflow" visible="true"/><rule ruleid="30428" enabled="true" group="136323129" action=" db  screen " name="D-Forum CGI脚本漏洞扫描探测" name_chs="D-Forum CGI脚本漏洞扫描探测" name_eng="D-Forum CGI Script Vulnerability Detection" visible="true"/><rule ruleid="30500" enabled="true" group="69208122" action=" db  screen " name="Lotus Domino文件名加点获取脚本源代码攻击" name_chs="Lotus Domino文件名加点获取脚本源代码攻击" name_eng="Lotus Domino Filename (appended with dot) Script Source Code Disclosure" visible="true"/><rule ruleid="30420" enabled="true" group="136323130" action=" db  screen " name="EditTag edittag.cgi脚本漏洞扫描探测" name_chs="EditTag edittag.cgi脚本漏洞扫描探测" name_eng="EditTag edittag.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30422" enabled="true" group="203431990" action=" db  screen " name="MyRoom save_item.php脚本漏洞扫描探测" name_chs="MyRoom save_item.php脚本漏洞扫描探测" name_eng="MyRoom save_item.php Script Vulnerability Detection" visible="true"/><rule ruleid="30423" enabled="true" group="136323125" action=" db  screen " name="Mambo Site Server脚本漏洞扫描探测" name_chs="Mambo Site Server脚本漏洞扫描探测" name_eng="Mambo Site Server Script Vulnerability Detection" visible="true"/><rule ruleid="30424" enabled="true" group="136323125" action=" db  screen " name="myphpPageTool CGI脚本漏洞扫描探测" name_chs="myphpPageTool CGI脚本漏洞扫描探测" name_eng="myphpPageTool CGI Script Vulnerability Detection" visible="true"/><rule ruleid="30426" enabled="true" group="136323126" action=" db  screen " name="FileSeek FileSeek.cgi脚本漏洞扫描探测" name_chs="FileSeek FileSeek.cgi脚本漏洞扫描探测" name_eng="FileSeek FileSeek.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30427" enabled="true" group="203431994" action=" db  screen " name="emailreader_execute_on_each_page.inc.php脚本漏洞扫描探测" name_chs="emailreader_execute_on_each_page.inc.php脚本漏洞扫描探测" name_eng="emailreader_execute_on_each_page.inc.php Script Vulnerability Detection" visible="true"/><rule ruleid="30190" enabled="true" group="69214266" action=" db  screen " name="Carey Internet Services commerce.cgi脚本漏洞扫描探测" name_chs="Carey Internet Services commerce.cgi脚本漏洞扫描探测" name_eng="Carey Internet Services commerce.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30191" enabled="true" group="136315066" action=" db  screen " name="利用Carey Internet Services commerce.cgi脚本漏洞远程遍历目录" name_chs="利用Carey Internet Services commerce.cgi脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via Carey Internet Services commerce.cgi Script Vulnerability" visible="true"/><rule ruleid="30193" enabled="true" group="136323126" action=" db  screen " name="Verity's Search`97 search97.vts脚本漏洞扫描探测" name_chs="Verity's Search`97 search97.vts脚本漏洞扫描探测" name_eng="Verity's Search`97 search97.vts Script Vulnerability Detection" visible="true"/><rule ruleid="30196" enabled="true" group="69206202" action=" db  screen " name="利用Microsoft IIS 3.0 &quot;%2e&quot; 漏洞获取ASP源码攻击" name_chs="利用Microsoft IIS 3.0 &quot;%2e&quot; 漏洞获取ASP源码攻击" name_eng="ASP Source Code Disclosure via Microsoft IIS 3.0 &quot;%2e&quot; Vulnerability" visible="true"/><rule ruleid="10092" enabled="true" group="75497767" action=" db  screen " name="CSM Mailserver HELO命令远程缓冲区溢出攻击" name_chs="CSM Mailserver HELO命令远程缓冲区溢出攻击" name_eng="CSM Mailserver HELO Command Remote Buffer Overflow" visible="true"/><rule ruleid="30198" enabled="true" group="151003190" action=" db  screen " name="SunOS rpc.selection_svc服务存在性TCP扫描探测" name_chs="SunOS rpc.selection_svc服务存在性TCP扫描探测" name_eng="SunOS rpc.selection_svc Service TCP Detection" visible="true"/><rule ruleid="30199" enabled="true" group="69206202" action=" db  screen " name="利用Microsoft IIS 3.0/4.0 &quot;%81&quot; 漏洞获取ASP源码攻击" name_chs="利用Microsoft IIS 3.0/4.0 &quot;%81&quot; 漏洞获取ASP源码攻击" name_eng="ASP Source Code Disclosure via Microsoft IIS 3.0/4.0 &quot;%81&quot; Vulnerability" visible="true"/><rule ruleid="30412" enabled="true" group="203431990" action=" db  screen " name="W-Agora editform.php脚本漏洞扫描探测" name_chs="W-Agora editform.php脚本漏洞扫描探测" name_eng="W-Agora editform.php Script Vulnerability Detection" visible="true"/><rule ruleid="10097" enabled="true" group="88081455" action=" db  screen  drop " name="Windows系统下MSSQL Slammer蠕虫攻击" name_chs="Windows系统下MSSQL Slammer蠕虫攻击" name_eng="Windows MSSQL Slammer" visible="true" merge="[t300,si]"/><rule ruleid="20286" enabled="true" group="154142759" action=" db  screen " name="AIX RLOGIN -froot非授权root用户访问攻击" name_chs="AIX RLOGIN -froot非授权root用户访问攻击" name_eng="AIX RLOGIN -froot Unauthorized root User Access" visible="true"/><rule ruleid="20281" enabled="true" group="69206187" action=" db  screen " name="利用Oracle Web Listener批处理文件远程执行命令" name_chs="利用Oracle Web Listener批处理文件远程执行命令" name_eng="File Batch Handling via Oracle Web Listener Remote Command Execution" visible="true"/><rule ruleid="20282" enabled="true" group="74449195" action=" db  screen " name="VanDyke SecureCRT SSH1协议处理远程缓冲区溢出攻击" name_chs="VanDyke SecureCRT SSH1协议处理远程缓冲区溢出攻击" name_eng="VanDyke SecureCRT SSH1 Protocol Handling Remote Buffer Overflow" visible="true"/><rule ruleid="30514" enabled="true" group="203423930" action=" db  screen " name="利用SquirrelMail CGI脚本漏洞远程浏览文件" name_chs="利用SquirrelMail CGI脚本漏洞远程浏览文件" name_eng="Remote File Browsing via SquirrelMail CGI Script Vulnerability" visible="true"/><rule ruleid="30515" enabled="true" group="136315070" action=" db  screen " name="Whois.Cart whoiscart脚本目录遍历攻击" name_chs="Whois.Cart whoiscart脚本目录遍历攻击" name_eng="Whois.Cart whoiscart Script Directory Traversal" visible="true"/><rule ruleid="20041" enabled="true" group="136323126" action=" db  screen " name="NCSA post-query程序漏洞扫描探测" name_chs="NCSA post-query程序漏洞扫描探测" name_eng="NCSA post-query Vulnerability Detection" visible="true"/><rule ruleid="20040" enabled="true" group="69214262" action=" db  screen " name="O'Reilly WebSite win-c-sample.exe CGI程序漏洞扫描探测" name_chs="O'Reilly WebSite win-c-sample.exe CGI程序漏洞扫描探测" name_eng="O'Reilly WebSite win-c-sample.exe CGI Vulnerability Detection" visible="true"/><rule ruleid="30510" enabled="true" group="136315066" action=" db  screen " name="利用EZshopper loadpage.cgi CGI脚本漏洞进行目录遍历攻击" name_chs="利用EZshopper loadpage.cgi CGI脚本漏洞进行目录遍历攻击" name_eng="Directory Traversal via EZshopper loadpage.cgi CGI Script Vulnerability" visible="true"/><rule ruleid="30511" enabled="true" group="203423930" action=" db  screen " name="Zeroboard多个CGI脚本目录遍历攻击" name_chs="Zeroboard多个CGI脚本目录遍历攻击" name_eng="Zeroboard multiple CGI Scripts Directory Traversal" visible="true"/><rule ruleid="10190" enabled="true" group="83888154" action=" db  screen " name="CA BrightStor ARCserve Backup caloggerd.exe远程拒绝服务攻击" name_chs="CA BrightStor ARCserve Backup caloggerd.exe远程拒绝服务攻击" name_eng="CA BrightStor ARCserve Backup caloggerd.exe Remote DoS Vulnerability" visible="true"/><rule ruleid="30518" enabled="true" group="203423934" action=" db  screen " name="PHP-Nuke modules.php远程目录遍历攻击" name_chs="PHP-Nuke modules.php远程目录遍历攻击" name_eng="PHP-Nuke modules.php Remote Directory Traversal" visible="true"/><rule ruleid="30519" enabled="true" group="233840702" action=" db  screen " name="端口扫描器PING Sweep操作" name_chs="端口扫描器PING Sweep操作" name_eng="Port Scanner PING Sweep Operation" visible="true"/><rule ruleid="30288" enabled="true" group="136315066" action=" db  screen " name="CGIScript.NET CSMailto.cgi脚本漏洞扫描利用" name_chs="CGIScript.NET CSMailto.cgi脚本漏洞扫描利用" name_eng="CGIScript.NET CSMailto.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30289" enabled="true" group="203423926" action=" db  screen " name="利用mcNews header.php脚本漏洞遍历目录" name_chs="利用mcNews header.php脚本漏洞遍历目录" name_eng="Directory Traversal via mcNews header.php Script Vulnerability" visible="true"/><rule ruleid="30284" enabled="true" group="136323126" action=" db  screen " name="Marcus S. directory.php脚本漏洞扫描探测" name_chs="Marcus S. directory.php脚本漏洞扫描探测" name_eng="Marcus S. directory.php Script Vulnerability Detection" visible="true"/><rule ruleid="30285" enabled="true" group="136315062" action=" db  screen " name="Sunsolve CD sscd_suncourier.pl脚本漏洞扫描利用" name_chs="Sunsolve CD sscd_suncourier.pl脚本漏洞扫描利用" name_eng="Sunsolve CD sscd_suncourier.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30286" enabled="true" group="203423930" action=" db  screen " name="PHPprojekt filemanager_forms.php脚本漏洞扫描利用" name_chs="PHPprojekt filemanager_forms.php脚本漏洞扫描利用" name_eng="PHPprojekt filemanager_forms.php Script Vulnerability Detection" visible="true"/><rule ruleid="30287" enabled="true" group="203423926" action=" db  screen " name="com.endymion.sake.servlet.mail.MailServlet脚本漏洞扫描利用" name_chs="com.endymion.sake.servlet.mail.MailServlet脚本漏洞扫描利用" name_eng="com.endymion.sake.servlet.mail.MailServlet Script Vulnerability Detection" visible="true"/><rule ruleid="30280" enabled="true" group="69206202" action=" db  screen " name="Hosting Controller filemanager.asp脚本利用扫描探测" name_chs="Hosting Controller filemanager.asp脚本利用扫描探测" name_eng="Hosting Controller filemanager.asp Script Detection" visible="true"/><rule ruleid="30281" enabled="true" group="69214261" action=" db  screen " name="Hosting Controller statsbrowse.asp系列脚本漏洞扫描探测" name_chs="Hosting Controller statsbrowse.asp系列脚本漏洞扫描探测" name_eng="Hosting Controller statsbrowse.asp Series Script Vulnerability Detection" visible="true"/><rule ruleid="30282" enabled="true" group="203423934" action=" db  screen " name="PostNuke user.php脚本漏洞扫描利用" name_chs="PostNuke user.php脚本漏洞扫描利用" name_eng="PostNuke user.php Script Vulnerability Detection" visible="true"/><rule ruleid="30283" enabled="true" group="69214270" action=" db  screen " name="Apache Win32批处理脚本漏洞扫描探测" name_chs="Apache Win32批处理脚本漏洞扫描探测" name_eng="Apache Win32 Batch Script Vulnerability Detection" visible="true"/><rule ruleid="30352" enabled="true" group="69206202" action=" db  screen " name="通过Web服务获取SmartWin CyberOffice Shopping Cart 2.0数据库文件" name_chs="通过Web服务获取SmartWin CyberOffice Shopping Cart 2.0数据库文件" name_eng="SmartWin CyberOffice Shopping Cart 2.0 Database File Disclosure via Web Service" visible="true"/><rule ruleid="30353" enabled="true" group="136315061" action=" db  screen " name="wwwboard.pl脚本漏洞扫描利用" name_chs="wwwboard.pl脚本漏洞扫描利用" name_eng="wwwboard.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30350" enabled="true" group="69206197" action=" db  screen " name="利用Talentsoft Web+获取内部IP地址攻击" name_chs="利用Talentsoft Web+获取内部IP地址攻击" name_eng="Internal IP Address Disclosure via Talentsoft Web+" visible="true"/><rule ruleid="30351" enabled="true" group="69206202" action=" db  screen " name="利用Talentsoft Web+漏洞获取脚本源码攻击" name_chs="利用Talentsoft Web+漏洞获取脚本源码攻击" name_eng="Script Source Code Disclosure via Talentsoft Web+ Vulnerability" visible="true"/><rule ruleid="30356" enabled="true" group="136323125" action=" db  screen " name="importInfo脚本漏洞扫描探测" name_chs="importInfo脚本漏洞扫描探测" name_eng="importInfo Script Vulnerability Detection" visible="true"/><rule ruleid="30357" enabled="true" group="136315062" action=" db  screen " name="利用importInfo脚本漏洞远程执行命令" name_chs="利用importInfo脚本漏洞远程执行命令" name_eng="Remote Code Execution via importInfo Script Vulnerability" visible="true"/><rule ruleid="30354" enabled="true" group="203423925" action=" db  screen " name="Phorum violation.php3脚本漏洞扫描利用" name_chs="Phorum violation.php3脚本漏洞扫描利用" name_eng="Phorum violation.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="30355" enabled="true" group="136323126" action=" db  screen " name="Web Portal customize.php脚本漏洞扫描探测" name_chs="Web Portal customize.php脚本漏洞扫描探测" name_eng="Web Portal customize.php Script Vulnerability Detection" visible="true"/><rule ruleid="30358" enabled="true" group="203423930" action=" db  screen " name="BadBlue soinfo.php脚本漏洞扫描利用" name_chs="BadBlue soinfo.php脚本漏洞扫描利用" name_eng="BadBlue soinfo.php Script Vulnerability Detection" visible="true"/><rule ruleid="30359" enabled="true" group="203423930" action=" db  screen " name="HTTPBench ezhttpbench.php脚本漏洞扫描利用" name_chs="HTTPBench ezhttpbench.php脚本漏洞扫描利用" name_eng="HTTPBench ezhttpbench.php Script Vulnerability Detection" visible="true"/><rule ruleid="40339" enabled="true" group="99618895" action=" db  screen " name="Windows系统下Matrix木马通信" name_chs="Windows系统下Matrix木马通信" name_eng="Trojan Matrix Communication on Windows" visible="true"/><rule ruleid="40338" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下NetBus木马通信" name_chs="Windows系统下NetBus木马通信" name_eng="Trojan NetBus Trojan Communication on Windows" visible="true"/><rule ruleid="50192" enabled="true" group="99745881" action=" db  screen " name="P2P文件共享工具脱兔进行文件下载" name_chs="P2P文件共享工具脱兔进行文件下载" name_eng="P2P File Sharing Tool Tuotu File Download" visible="true"/><rule ruleid="40448" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Doly Trojan 1.6木马建立连接" name_chs="Windows系统下Doly Trojan 1.6木马建立连接" name_eng="Doly Trojan 1.6 Connection on Windows" visible="true"/><rule ruleid="50190" enabled="true" group="68223065" action=" db  screen " name="HTTP协议Chunked数据编码异常" name_chs="HTTP协议Chunked数据编码异常" name_eng="HTTP Protocol Chunked Data Coding Anomaly" visible="true"/><rule ruleid="50196" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具eDonkey/ed2k请求文件片断(UDP)" name_chs="P2P文件共享工具eDonkey/ed2k请求文件片断(UDP)" name_eng="P2P File Sharing Tool eDonkey/ed2k Request File Fragment (UDP)" visible="true"/><rule ruleid="50197" enabled="true" group="68288605" action=" db  screen " name="BitComet通过HTTP协议进行文件下载" name_chs="BitComet通过HTTP协议进行文件下载" name_eng="BitComet Downloading Files Through HTTP Protocol" visible="true"/><rule ruleid="50194" enabled="true" group="99680345" action=" db  screen " name="网络代理软件SocksOnline数据通信" name_chs="网络代理软件SocksOnline数据通信" name_eng="Network Agent Software SocksOnline Data Communication" visible="true"/><rule ruleid="50195" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具迅雷文件下载(UDP)" name_chs="P2P文件共享工具迅雷文件下载(UDP)" name_eng="P2P File Sharing Tool Xunlei File Downloading (UDP)" visible="true"/><rule ruleid="50199" enabled="true" group="68223069" action=" db  screen " name="Google网络爬虫抓取网页信息" name_chs="Google网络爬虫抓取网页信息" name_eng="Google Web Crawlers Capture Page Information" visible="true"/><rule ruleid="40445" enabled="true" group="204505162" action=" db  screen " name="FTP服务Bounce跳转攻击" name_chs="FTP服务Bounce跳转攻击" name_eng="FTP Service Bounce Attack" visible="true"/><rule ruleid="40447" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Doly Trojan 2.0木马建立连接" name_chs="Windows系统下Doly Trojan 2.0木马建立连接" name_eng="Doly Trojan 2.0 Connection on Windows" visible="true"/><rule ruleid="40446" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下NetBus Pro木马通信" name_chs="Windows系统下NetBus Pro木马通信" name_eng="Trojan NetBus Pro Communication on Windows" visible="true"/><rule ruleid="10096" enabled="true" group="70256663" action=" db  screen " name="Platinum FTP Server远程拒绝服务攻击" name_chs="Platinum FTP Server远程拒绝服务攻击" name_eng="Platinum FTP Server Remote Denial of Service" visible="true"/><rule ruleid="10095" enabled="true" group="136315035" action=" db  screen " name="利用PHP-Nuke modules.php脚本漏洞拒绝服务攻击" name_chs="利用PHP-Nuke modules.php脚本漏洞拒绝服务攻击" name_eng="Denial of Service via PHP-Nuke modules.php Script Vulnerability" visible="true"/><rule ruleid="40364" enabled="true" group="209723449" action=" db  screen " name="SMTP服务EXPN命令请求" name_chs="SMTP服务EXPN命令请求" name_eng="SMTP Service EXPN Command Request" visible="true"/><rule ruleid="50048" enabled="true" group="210829402" action=" db  screen " name="IMAP服务用户弱口令认证" name_chs="IMAP服务用户弱口令认证" name_eng="IMAP Service Weak User Password Authentication" visible="true" merge="[t86400,si,di]"/><rule ruleid="50049" enabled="true" group="205586525" action=" db  screen " name="TELNET服务用户认证" name_chs="TELNET服务用户认证" name_eng="TELNET Service User Authentication" visible="true"/><rule ruleid="40365" enabled="true" group="209723449" action=" db  screen " name="SMTP服务VRFY命令请求" name_chs="SMTP服务VRFY命令请求" name_eng="SMTP Service VRFY Command Request" visible="true"/><rule ruleid="50044" enabled="true" group="206635101" action=" db  screen " name="POP3服务用户认证" name_chs="POP3服务用户认证" name_eng="POP3 Service User Authentication" visible="true" merge="[t7200,si,di]"/><rule ruleid="50045" enabled="true" group="204537949" action=" db  screen " name="FTP服务用户弱口令认证" name_chs="FTP服务用户弱口令认证" name_eng="FTP Service User Weak Password Authentication" visible="true" merge="[t86400,si,di]"/><rule ruleid="50047" enabled="true" group="206635102" action=" db  screen " name="POP3服务用户弱口令认证" name_chs="POP3服务用户弱口令认证" name_eng="POP3 Service Weak User Password Authentication" visible="true" merge="[t86400,si,di]"/><rule ruleid="50040" enabled="false" group="72613967" action=" db  screen " name="POP3服务接收可疑病毒邮件" name_chs="POP3服务接收可疑病毒邮件" name_eng="POP3 Service Receiving Mails with Suspicious Virus" visible="true" merge="[t7200,si,di]"/><rule ruleid="40366" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht服务器回应" name_chs="DDOS工具Stacheldraht服务器回应" name_eng="DDOS Stacheldraht Server Response" visible="true"/><rule ruleid="50043" enabled="true" group="206635101" action=" db  screen " name="POP3服务用户认证" name_chs="POP3服务用户认证" name_eng="POP3 Service User Authentication" visible="true" merge="[t7200,si,di]"/><rule ruleid="40367" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Stacheldraht客户端操作" name_chs="DDOS工具Stacheldraht客户端操作" name_eng="DDOS Stacheldraht Client Operation" visible="true"/><rule ruleid="40363" enabled="true" group="209723450" action=" db  screen " name="SMTP服务EXPN命令系统帐号存在性探测" name_chs="SMTP服务EXPN命令系统帐号存在性探测" name_eng="SMTP Service EXPN Command System Account Detection" visible="true"/><rule ruleid="30033" enabled="true" group="211820602" action=" db  screen " name="DNS服务区信息传输请求操作" name_chs="DNS服务区信息传输请求操作" name_eng="DNS Service Zone Information Transmission Request" visible="true"/><rule ruleid="30292" enabled="true" group="69206202" action=" db  screen " name="Hosting Controller dsnmanager.asp脚本漏洞扫描探测" name_chs="Hosting Controller dsnmanager.asp脚本漏洞扫描探测" name_eng="Hosting Controller dsnmanager.asp Script Vulnerability Detection" visible="true"/><rule ruleid="20708" enabled="true" group="99615019" action=" db  screen " name="SIPfoundry sipXtapi畸形CSeq字段处理远程缓冲区溢出攻击" name_chs="SIPfoundry sipXtapi畸形CSeq字段处理远程缓冲区溢出攻击" name_eng="SIPfoundry sipXtapi Malformed CSeq Field Handling Remote Buffer Overflow" visible="true"/><rule ruleid="20709" enabled="true" group="203423915" action=" db  screen " name="Sabdrimer CMS advanced1.php远程文件包含攻击" name_chs="Sabdrimer CMS advanced1.php远程文件包含攻击" name_eng="Sabdrimer CMS advanced1.php Remote File Inclusion" visible="true"/><rule ruleid="20700" enabled="true" group="203423915" action=" db  screen " name="SaveWebPortal SITE_Path变量远程文件包含攻击" name_chs="SaveWebPortal SITE_Path变量远程文件包含攻击" name_eng="SaveWebPortal SITE_Path Variable Remote File Inclusion" visible="true"/><rule ruleid="20701" enabled="true" group="203423915" action=" db  screen " name="The Search Engine Project (TSEP) colorswitch.php远程文件包含攻击" name_chs="The Search Engine Project (TSEP) colorswitch.php远程文件包含攻击" name_eng="The Search Engine Project (TSEP) colorswitch.php Remote File Inclusion" visible="true"/><rule ruleid="20702" enabled="true" group="203423915" action=" db  screen " name="Knusperleicht ShoutBox SB_INCLUDE_PATH参数远程文件包含攻击" name_chs="Knusperleicht ShoutBox SB_INCLUDE_PATH参数远程文件包含攻击" name_eng="Knusperleicht ShoutBox SB_INCLUDE_PATH Variable Remote File Inclusion" visible="true"/><rule ruleid="20703" enabled="true" group="203423915" action=" db  screen " name="MyNewsGroups layersmenu.inc.php远程文件包含攻击" name_chs="MyNewsGroups layersmenu.inc.php远程文件包含攻击" name_eng="MyNewsGroups layersmenu.inc.php Remote File Inclusion" visible="true"/><rule ruleid="20704" enabled="true" group="70254891" action=" db  screen " name="Easy File Sharing FTP Server超长PASS命令参数远程缓冲区溢出攻击" name_chs="Easy File Sharing FTP Server超长PASS命令参数远程缓冲区溢出攻击" name_eng="Easy File Sharing FTP Server Over-long PASS Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20705" enabled="true" group="203423915" action=" db  screen " name="Mambo VideoDB组件远程文件包含攻击" name_chs="Mambo VideoDB组件远程文件包含攻击" name_eng="Mambo VideoDB Component Remote File Inclusion" visible="true"/><rule ruleid="20706" enabled="true" group="70254891" action=" db  screen " name="Intervations FileCopa LIST命令远程缓冲区溢出攻击" name_chs="Intervations FileCopa LIST命令远程缓冲区溢出攻击" name_eng="Intervations FileCopa LIST Command Remote Buffer Overflow" visible="true"/><rule ruleid="20707" enabled="true" group="203423915" action=" db  screen " name="MiniBB absolute_path参数远程文件包含攻击" name_chs="MiniBB absolute_path参数远程文件包含攻击" name_eng="MiniBB absolute_path Variable Remote File Inclusion" visible="true"/><rule ruleid="30291" enabled="true" group="69206202" action=" db  screen " name="Hosting Controller browse.asp脚本漏洞扫描利用" name_chs="Hosting Controller browse.asp脚本漏洞扫描利用" name_eng="Hosting Controller browse.asp Script Vulnerability Detection" visible="true"/><rule ruleid="20166" enabled="true" group="138412335" action=" db  screen " name="BSD系统telnetd远程堆溢出漏洞探测" name_chs="BSD系统telnetd远程堆溢出漏洞探测" name_eng="BSD System telnetd Remote Heap Overflow Detection" visible="true"/><rule ruleid="20167" enabled="true" group="150995243" action=" db  screen " name="Solaris rpc.ttdbserverd远程缓冲区溢出攻击" name_chs="Solaris rpc.ttdbserverd远程缓冲区溢出攻击" name_eng="Solaris rpc.ttdbserverd Remote Buffer Overflow" visible="true"/><rule ruleid="20165" enabled="true" group="138412335" action=" db  screen  drop " name="BSD系统telnetd远程堆溢出漏洞攻击" name_chs="BSD系统telnetd远程堆溢出漏洞攻击" name_eng="BSD System telnetd Remote Heap Overflow" visible="true"/><rule ruleid="20674" enabled="true" group="203423914" action=" db  screen " name="Easynews绕过管理认证攻击" name_chs="Easynews绕过管理认证攻击" name_eng="Easynews Admin Authentication Bypass" visible="true"/><rule ruleid="20675" enabled="true" group="203423915" action=" db  screen " name="P-News p-news.php远程文件包含攻击" name_chs="P-News p-news.php远程文件包含攻击" name_eng="P-News p-news.php Remote File Inclusion" visible="true"/><rule ruleid="20676" enabled="true" group="203423915" action=" db  screen " name="MiniBB bb_func_txt.php远程文件包含攻击" name_chs="MiniBB bb_func_txt.php远程文件包含攻击" name_eng="MiniBB bb_func_txt.php Remote File Inclusion" visible="true"/><rule ruleid="20677" enabled="true" group="203423915" action=" db  screen " name="TextPattern txpcfg[txpath]变量远程文件包含攻击" name_chs="TextPattern txpcfg[txpath]变量远程文件包含攻击" name_eng="TextPattern txpcfg[txpath] Variable Remote File Inclusion" visible="true"/><rule ruleid="20670" enabled="true" group="203423915" action=" db  screen " name="PowerPortal file_name[]变量远程文件包含攻击" name_chs="PowerPortal file_name[]变量远程文件包含攻击" name_eng="PowerPortal file_name[] Variable Remote File Inclusion" visible="true"/><rule ruleid="20671" enabled="true" group="203423915" action=" db  screen " name="Freenews chemin变量远程文件包含攻击" name_chs="Freenews chemin变量远程文件包含攻击" name_eng="Freenews chemin Variable Remote File Inclusion" visible="true"/><rule ruleid="20672" enabled="true" group="203423915" action=" db  screen " name="PHP Live! help.php远程文件包含攻击" name_chs="PHP Live! help.php远程文件包含攻击" name_eng="PHP Live! help.php Remote File Inclusion" visible="true"/><rule ruleid="20673" enabled="true" group="203423915" action=" db  screen " name="NuralStorm Webmail DEFAULT_SKIN变量远程文件包含攻击" name_chs="NuralStorm Webmail DEFAULT_SKIN变量远程文件包含攻击" name_eng="NuralStorm Webmail DEFAULT_SKIN Variable Remote File Inclusion" visible="true"/><rule ruleid="20678" enabled="true" group="203423915" action=" db  screen " name="MySource CMS INCLUDE_PATH变量远程文件包含攻击" name_chs="MySource CMS INCLUDE_PATH变量远程文件包含攻击" name_eng="MySource CMS INCLUDE_PATH Variable Remote File Inclusion" visible="true"/><rule ruleid="20679" enabled="true" group="99615019" action=" db  screen " name="Novell eDirectory/iMonitor HTTP协议畸形HOST字段缓冲区溢出攻击" name_chs="Novell eDirectory/iMonitor HTTP协议畸形HOST字段缓冲区溢出攻击" name_eng="Novell eDirectory/iMonitor HTTP Protocol Malformed HOST Field Remote Buffer Overflow" visible="true"/><rule ruleid="40770" enabled="true" group="368054347" action=" db  screen " name="Windows系统下Theef木马活动通信" name_chs="Windows系统下Theef木马活动通信" name_eng="Trojan Theef Trojan Communication on Windows" visible="true"/><rule ruleid="40746" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware MySearch下载安装程序" name_chs="Windows系统下Adware MySearch下载安装程序" name_eng="Adware MySearch Downloading Installer on Windows" visible="true"/><rule ruleid="30528" enabled="false" group="88088638" action=" db  screen " name="Microsoft SQL Server登录获取版本信息" name_chs="Microsoft SQL Server登录获取版本信息" name_eng="Microsoft SQL Server Login Version Information Disclosure" visible="true"/><rule ruleid="20450" enabled="true" group="203423915" action=" db  screen " name="利用ocPortal index.php脚本漏洞远程执行命令" name_chs="利用ocPortal index.php脚本漏洞远程执行命令" name_eng="Remote Command Execution via ocPortal index.php Script Vulnerability" visible="true"/><rule ruleid="20907" enabled="true" group="202375338" action=" db  screen " name="WordPress插件远程文件包含攻击" name_chs="WordPress插件远程文件包含攻击" name_eng="WordPress Plugin Remote File Inclusion" visible="true"/><rule ruleid="20904" enabled="true" group="202375338" action=" db  screen " name="MyBB calendar.php脚本远程SQL注入攻击" name_chs="MyBB calendar.php脚本远程SQL注入攻击" name_eng="MyBB calendar.php Script Remote SQL Injection" visible="true"/><rule ruleid="20905" enabled="true" group="202375338" action=" db  screen " name="WEBinsta FM login.php远程文件包含攻击" name_chs="WEBinsta FM login.php远程文件包含攻击" name_eng="WEBinsta FM login.php Remote File Inclusion" visible="true"/><rule ruleid="20902" enabled="true" group="68157738" action=" db  screen " name="雅虎通Webcam Viewer ActiveX控件远程栈溢出攻击" name_chs="雅虎通Webcam Viewer ActiveX控件远程栈溢出攻击" name_eng="Yahoo! Messenger Webcam Viewer ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="20903" enabled="true" group="68157738" action=" db  screen " name="雅虎通Webcam Upload ActiveX控件远程栈溢出攻击" name_chs="雅虎通Webcam Upload ActiveX控件远程栈溢出攻击" name_eng="Yahoo! Messenger Webcam Upload ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="20900" enabled="true" group="68157738" action=" db  screen " name="联众ConnectAndEnterRoom ActiveX控件栈溢出攻击" name_chs="联众ConnectAndEnterRoom ActiveX控件栈溢出攻击" name_eng="Ourgame ConnectAndEnterRoom ActiveX Control Stack Overflow" visible="true"/><rule ruleid="20901" enabled="true" group="68157738" action=" db  screen " name="SonicWALL SSL-VPN ActiveX控件远程缓冲区溢出攻击" name_chs="SonicWALL SSL-VPN ActiveX控件远程缓冲区溢出攻击" name_eng="SonicWALL SSL-VPN ActiveX Control Remote Buffer Overflow" visible="true"/><rule ruleid="20458" enabled="true" group="135266607" action=" db  screen " name="Apache_W32 Web Server分块编码传输方式远程溢出攻击" name_chs="Apache_W32 Web Server分块编码传输方式远程溢出攻击" name_eng="Apache_W32 Web Server Chunked Encoding Transmission Remote Buffer Overflow" visible="true"/><rule ruleid="20459" enabled="true" group="203423919" action=" db  screen " name="UBBThreads dosearch.php远程SQL注入攻击" name_chs="UBBThreads dosearch.php远程SQL注入攻击" name_eng="UBBThreads dosearch.php Remote SQL Injection" visible="true"/><rule ruleid="30153" enabled="true" group="136323126" action=" db  screen " name="BNBForm bnbform.cgi脚本漏洞扫描探测" name_chs="BNBForm bnbform.cgi脚本漏洞扫描探测" name_eng="BNBForm bnbform.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30295" enabled="true" group="136323125" action=" db  screen " name="AdMentor系列脚本漏洞扫描探测" name_chs="AdMentor系列脚本漏洞扫描探测" name_eng="AdMentor Series Script Vulnerability Detection" visible="true"/><rule ruleid="20908" enabled="true" group="68157738" action=" db  screen " name="迅雷PPLAYER.DLL_1_WORK ActiveX控件缓冲区溢出攻击" name_chs="迅雷PPLAYER.DLL_1_WORK ActiveX控件缓冲区溢出攻击" name_eng="Xunlei PPLAYER.DLL_1_WORK ActiveX Control Buffer Overflow" visible="true"/><rule ruleid="20909" enabled="true" group="233832746" action=" db  screen " name="Borland InterBase ibserver.exe远程栈缓冲区溢出攻击" name_chs="Borland InterBase ibserver.exe远程栈缓冲区溢出攻击" name_eng="Borland InterBase ibserver.exe Remote Stack Buffer Overflow" visible="true"/><rule ruleid="40748" enabled="true" group="99618891" action=" db  screen " name="Windows系统下BDoor木马通信" name_chs="Windows系统下BDoor木马通信" name_eng="Trojan BDoor Communication on Windows" visible="true"/><rule ruleid="30254" enabled="true" group="136323130" action=" db  screen " name="site_searcher.cgi脚本漏洞扫描探测" name_chs="site_searcher.cgi脚本漏洞扫描探测" name_eng="site_searcher.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30521" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－RESET扫描" name_chs="服务器端口扫描－RESET扫描" name_eng="Server Port Scan - RESET Scan" visible="true"/><rule ruleid="40804" enabled="true" group="68223050" action=" db  screen " name="Microsoft IE畸形VML文档处理缓冲区溢出攻击" name_chs="Microsoft IE畸形VML文档处理缓冲区溢出攻击" name_eng="Microsoft IE Malformed VML Document Handling Buffer Overflow" visible="true"/><rule ruleid="30251" enabled="true" group="136315066" action=" db  screen " name="访问&quot;/globals.jsa&quot;获取Oracle 9iAS配置信息攻击" name_chs="访问&quot;/globals.jsa&quot;获取Oracle 9iAS配置信息攻击" name_eng="Oracle 9iAS Config Information Disclosure via &quot;/globals.jsa&quot;" visible="true"/><rule ruleid="30522" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－SYNACK扫描" name_chs="服务器端口扫描－SYNACK扫描" name_eng="Server Port Scan - SYNACK Scan" visible="true"/><rule ruleid="30168" enabled="true" group="136323130" action=" db  screen " name="Matt Kruse calendar-admin.pl脚本漏洞扫描探测" name_chs="Matt Kruse calendar-admin.pl脚本漏洞扫描探测" name_eng="Matt Kruse calendar-admin.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30165" enabled="true" group="69214270" action=" db  screen " name="Microsoft IIS 5.0 codebrws.asp脚本漏洞扫描探测" name_chs="Microsoft IIS 5.0 codebrws.asp脚本漏洞扫描探测" name_eng="Microsoft IIS 5.0 codebrws.asp Script Vulnerability Detection" visible="true"/><rule ruleid="30164" enabled="true" group="69206206" action=" db  screen " name="利用Microsoft IIS 4.0 showcode.asp脚本漏洞遍历目录读取文件" name_chs="利用Microsoft IIS 4.0 showcode.asp脚本漏洞遍历目录读取文件" name_eng="Directory Traversal File Reading via Microsoft IIS 4.0 showcode.asp Script Vulnerability" visible="true"/><rule ruleid="30167" enabled="true" group="136323130" action=" db  screen " name="Matt Kruse calendar.pl脚本漏洞扫描探测" name_chs="Matt Kruse calendar.pl脚本漏洞扫描探测" name_eng="Matt Kruse calendar.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30166" enabled="true" group="69206202" action=" db  screen " name="利用Microsoft IIS 5.0 codebrws.asp脚本漏洞遍历目录读取文件" name_chs="利用Microsoft IIS 5.0 codebrws.asp脚本漏洞遍历目录读取文件" name_eng="Directory Traversal File Reading via Microsoft IIS 5.0 codebrws.asp Script Vulnerability" visible="true"/><rule ruleid="30160" enabled="true" group="69206206" action=" db  screen " name="Microsoft IIS 4.0 FrontPage 98扩展察看CGI脚本源代码攻击" name_chs="Microsoft IIS 4.0 FrontPage 98扩展察看CGI脚本源代码攻击" name_eng="Microsoft IIS 4.0 FrontPage 98 Extension CGI Script Source Code Disclosure" visible="true"/><rule ruleid="30163" enabled="true" group="69214270" action=" db  screen " name="Microsoft IIS 4.0 showcode.asp脚本漏洞扫描探测" name_chs="Microsoft IIS 4.0 showcode.asp脚本漏洞扫描探测" name_eng="Microsoft IIS 4.0 showcode.asp Script Vulnerability Detection" visible="true"/><rule ruleid="30162" enabled="true" group="136323130" action=" db  screen " name="Rod Clark sendform.cgi脚本漏洞扫描探测" name_chs="Rod Clark sendform.cgi脚本漏洞扫描探测" name_eng="Rod Clark sendform.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="20296" enabled="true" group="166725679" action=" db  screen " name="Sun Solaris kcms_server远程读取任意文件攻击" name_chs="Sun Solaris kcms_server远程读取任意文件攻击" name_eng="Sun Solaris kcms_server Remote Arbitrary File Reading" visible="true"/><rule ruleid="20297" enabled="true" group="95420715" action=" db  screen " name="Microsoft Windows Locator服务远程缓冲区溢出攻击" name_chs="Microsoft Windows Locator服务远程缓冲区溢出攻击" name_eng="Microsoft Windows Locator Service Remote Buffer Overflow" visible="true"/><rule ruleid="20294" enabled="true" group="136315047" action=" db  screen " name="利用psunami.cgi脚本漏洞远程执行命令" name_chs="利用psunami.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via psunami.cgi Script Vulnerability" visible="true"/><rule ruleid="20295" enabled="true" group="222300207" action=" db  screen  drop " name="MySQL COM_CHANGE_USER功能口令认证缺陷漏洞攻击" name_chs="MySQL COM_CHANGE_USER功能口令认证缺陷漏洞攻击" name_eng="MySQL COM_CHANGE_USER Function Password Authentication Vulnerability" visible="true"/>
  <rule ruleid="20292" enabled="true" group="203423911" action=" db  screen " name="利用DCP-Portal lib.php脚本漏洞远程执行命令" name_chs="利用DCP-Portal lib.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via DCP-Portal lib.php Script Vulnerability" visible="true"/>

  <rule ruleid="20293" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.ttdbserverd远程堆溢出攻击" name_chs="Solaris rpc.ttdbserverd远程堆溢出攻击" name_eng="Solaris rpc.ttdbserverd Remote Stack Overflow" visible="true"/>
  
  <rule ruleid="20290" enabled="true" group="136315051" action=" db  screen " name="利用Open WebMail openwebmail-shared.pl脚本漏洞远程执行命令" name_chs="利用Open WebMail openwebmail-shared.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via Open WebMail openwebmail-shared.pl Script Vulnerability" visible="true"/>
  <rule ruleid="20291" enabled="true" group="136315051" action=" db  screen " name="利用Active PHP Bookmarks脚本漏洞远程执行命令" name_chs="利用Active PHP Bookmarks脚本漏洞远程执行命令" name_eng="Remote Code Execution via Active PHP Bookmarks Script Vulnerability" visible="true"/>
  <rule ruleid="40146" enabled="true" group="68157647" action=" db  screen " name="通过Web服务执行tftp.exe程序" name_chs="通过Web服务执行tftp.exe程序" name_eng="tftp.exe Program Execution via Web Service" visible="true"/>
  <rule ruleid="40148" enabled="true" group="69206223" action=" db  screen " name="通过Web服务执行cmd.exe程序" name_chs="通过Web服务执行cmd.exe程序" name_eng="cmd.exe Program Execution via Web Service" visible="true"/><rule ruleid="50211" enabled="true" group="233963613" action=" db  screen " name="SopCast网络电视流媒体播放(TCP)" name_chs="SopCast网络电视流媒体播放(TCP)" name_eng="SopCast Network TV Streaming Media Playing (TCP)" visible="true"/><rule ruleid="50210" enabled="true" group="233963613" action=" db  screen " name="SopCast网络电视流媒体播放(UDP)" name_chs="SopCast网络电视流媒体播放(UDP)" name_eng="SopCast Network TV Streaming Media Playing (UDP)" visible="true"/><rule ruleid="50213" enabled="true" group="233963613" action=" db  screen " name="NEO(泥巴网)网络电视流媒体播放(UDP)" name_chs="NEO(泥巴网)网络电视流媒体播放(UDP)" name_eng="NEO(nibaa.tv) Network TV Streaming Media Playing (UDP)" visible="true"/><rule ruleid="50212" enabled="true" group="233963613" action=" db  screen " name="FLV视频文件在线流媒体播放" name_chs="FLV视频文件在线流媒体播放" name_eng="FLV Video File Online Streaming Media Playing" visible="true"/><rule ruleid="50215" enabled="true" group="233963613" action=" db  screen " name="TVUPlayer网络电视流媒体播放(TCP)" name_chs="TVUPlayer网络电视流媒体播放(TCP)" name_eng="TVUPlayer Network TV Streaming Media Playing (TCP)" visible="true"/><rule ruleid="50214" enabled="true" group="233963613" action=" db  screen " name="TVUPlayer网络电视流媒体播放(UDP)" name_chs="TVUPlayer网络电视流媒体播放(UDP)" name_eng="TVUPlayer Network TV Streaming Media Playing (UDP)" visible="true"/><rule ruleid="50217" enabled="true" group="68223069" action=" db  screen " name="股票行情分析操作软件渤海证券用户登录" name_chs="股票行情分析操作软件渤海证券用户登录" name_eng="Stock Market Analysis Software Bohai Securities User Login" visible="true"/><rule ruleid="50216" enabled="true" group="68223069" action=" db  screen " name="股票行情分析操作软件飞天行情分析系统用户登录" name_chs="股票行情分析操作软件飞天行情分析系统用户登录" name_eng="Stock Market Analysis Software Feitian Market Analysis System User Login" visible="true"/><rule ruleid="50219" enabled="true" group="68223069" action=" db  screen " name="股票行情分析操作软件中信证券用户登录" name_chs="股票行情分析操作软件中信证券用户登录" name_eng="Stock Market Analysing Operating System Citic Securities User Login" visible="true"/><rule ruleid="50218" enabled="true" group="99680345" action=" db  screen " name="边锋网络游戏世界用户登陆" name_chs="边锋网络游戏世界用户登陆" name_eng="Bianfeng Network Web Game User Login" visible="true"/><rule ruleid="30369" enabled="true" group="136315062" action=" db  screen " name="利用Sojourn sojourn.cgi脚本漏洞读取文件" name_chs="利用Sojourn sojourn.cgi脚本漏洞读取文件" name_eng="File Reading via Sojourn sojourn.cgi Script Vulnerability" visible="true"/><rule ruleid="30368" enabled="true" group="136315066" action=" db  screen " name="CGI-World Poll脚本漏洞扫描探测" name_chs="CGI-World Poll脚本漏洞扫描探测" name_eng="CGI-World Poll Script Vulnerability Detection" visible="true"/><rule ruleid="30367" enabled="true" group="136315066" action=" db  screen " name="利用CGI-World Poll CGI脚本漏洞获取系统文件" name_chs="利用CGI-World Poll CGI脚本漏洞获取系统文件" name_eng="System File Disclosure via CGI-World Poll CGI Script Vulnerability" visible="true"/><rule ruleid="30366" enabled="true" group="136315065" action=" db  screen " name="利用OpenLinux rpm_query CGI获取系统RPM包安装信息" name_chs="利用OpenLinux rpm_query CGI获取系统RPM包安装信息" name_eng="RPM Package Installation Detection via OpenLinux rpm_query CGI" visible="true"/><rule ruleid="30365" enabled="true" group="203423925" action=" db  screen " name="PhpSmsSend smssend.php脚本漏洞扫描利用" name_chs="PhpSmsSend smssend.php脚本漏洞扫描利用" name_eng="PhpSmsSend smssend.php Script Vulnerability Detection" visible="true"/><rule ruleid="30364" enabled="true" group="135266494" action=" db  screen " name="通过Web服务访问.htaccess文件" name_chs="通过Web服务访问.htaccess文件" name_eng="Access to .htaccess file via Web Service" visible="true"/><rule ruleid="30363" enabled="true" group="136315062" action=" db  screen " name="利用Way-Board way-board.cgi脚本漏洞远程浏览文件" name_chs="利用Way-Board way-board.cgi脚本漏洞远程浏览文件" name_eng="Remote File Viewing via Way-Board way-board.cgi Script Vulnerability" visible="true"/><rule ruleid="30361" enabled="true" group="203423934" action=" db  screen " name="利用PHP-Nuke admin.php脚本漏洞浏览本地文件" name_chs="利用PHP-Nuke admin.php脚本漏洞浏览本地文件" name_eng="Local File Browsing via PHP-Nuke admin.php Script Vulnerability" visible="true"/><rule ruleid="40646" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Bagz蠕虫病毒邮件" name_chs="SMTP服务发送W32.Bagz蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Bagz" visible="true"/><rule ruleid="30385" enabled="true" group="203431994" action=" db  screen " name="SquirrelMail left_main.php脚本漏洞扫描探测" name_chs="SquirrelMail left_main.php脚本漏洞扫描探测" name_eng="SquirrelMail left_main.php Script Vulnerability Detection" visible="true"/><rule ruleid="30384" enabled="true" group="203431994" action=" db  screen " name="SquirrelSpell check_me.mod.php脚本漏洞扫描探测" name_chs="SquirrelSpell check_me.mod.php脚本漏洞扫描探测" name_eng="SquirrelSpell check_me.mod.php Script Vulnerability Detection" visible="true"/><rule ruleid="30387" enabled="true" group="203431994" action=" db  screen " name="Oracle Reports Server rwcgi60脚本漏洞扫描探测" name_chs="Oracle Reports Server rwcgi60脚本漏洞扫描探测" name_eng="Oracle Reports Server rwcgi60 Script Vulnerability Detection" visible="true"/><rule ruleid="30386" enabled="true" group="203431989" action=" db  screen " name="Messagerie supp_membre.php脚本漏洞扫描探测" name_chs="Messagerie supp_membre.php脚本漏洞扫描探测" name_eng="Messagerie supp_membre.php Script Vulnerability Detection" visible="true"/><rule ruleid="30381" enabled="true" group="69214266" action=" db  screen " name="Webspeed wsisa.dll脚本漏洞扫描探测" name_chs="Webspeed wsisa.dll脚本漏洞扫描探测" name_eng="Webspeed wsisa.dll Script Vulnerability Detection" visible="true"/><rule ruleid="30380" enabled="true" group="136315066" action=" db  screen " name="SWSoft ASPSeek s.cgi CGI程序漏洞扫描探测" name_chs="SWSoft ASPSeek s.cgi CGI程序漏洞扫描探测" name_eng="SWSoft ASPSeek s.cgi CGI Vulnerability Detection" visible="true"/><rule ruleid="30383" enabled="true" group="203431989" action=" db  screen " name="Blahz-DNS dostuff.php脚本漏洞扫描探测" name_chs="Blahz-DNS dostuff.php脚本漏洞扫描探测" name_eng="Blahz-DNS dostuff.php Script Vulnerability Detection" visible="true"/><rule ruleid="30382" enabled="true" group="203431989" action=" db  screen " name="DNSTools dnstools.php脚本漏洞扫描探测" name_chs="DNSTools dnstools.php脚本漏洞扫描探测" name_eng="DNSTools dnstools.php Script Vulnerability Detection" visible="true"/><rule ruleid="40452" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Lovgate蠕虫病毒邮件" name_chs="SMTP服务发送W32.Lovgate蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Lovgate" visible="true"/><rule ruleid="40453" enabled="true" group="72613967" action=" db  screen " name="POP3服务接收W32.Lovgate蠕虫病毒邮件" name_chs="POP3服务接收W32.Lovgate蠕虫病毒邮件" name_eng="POP3 Service Receiving Mails with the W32.Lovgate" visible="true"/><rule ruleid="40450" enabled="true" group="99615819" action=" db  screen " name="Windows系统Nimda蠕虫利用共享传播" name_chs="Windows系统Nimda蠕虫利用共享传播" name_eng="Worm Nimda Propagation on Windows via Sharing" visible="true"/><rule ruleid="40451" enabled="true" group="95682635" action=" db  screen " name="Windows系统求职信病毒利用共享传播" name_chs="Windows系统求职信病毒利用共享传播" name_eng="Worm.Klez Propagation on Windows via Sharing" visible="true"/><rule ruleid="30389" enabled="true" group="136315065" action=" db  screen " name="通过访问SnoopServlet Servlet获取服务器软件安装路径信息" name_chs="通过访问SnoopServlet Servlet获取服务器软件安装路径信息" name_eng="Server Installation Path Disclosure from SnoopServlet Servlet" visible="true"/><rule ruleid="30388" enabled="true" group="136315065" action=" db  screen " name="访问TroubleShooter Servlet获取服务器软件安装路径信息" name_chs="访问TroubleShooter Servlet获取服务器软件安装路径信息" name_eng="Server Installation Path Disclosure from TroubleShooter Servlet" visible="true"/><rule ruleid="40454" enabled="true" group="95682639" action=" db  screen " name="Windows系统下W32.Lovgate蠕虫病毒通过共享传播" name_chs="Windows系统下W32.Lovgate蠕虫病毒通过共享传播" name_eng="W32.Lovgate Propagation by Sharing on Windows" visible="true"/><rule ruleid="40455" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Bugbear.B@mm蠕虫病毒的窃密邮件" name_chs="SMTP服务发送W32.Bugbear.B@mm蠕虫病毒的窃密邮件" name_eng="SMTP Service Sending Information Theft Mails with W32.Bugbear.B@mm" visible="true"/><rule ruleid="50094" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN用户音频聊天" name_chs="即时通信软件MSN用户音频聊天" name_eng="Instant Messaging Software MSN User Audio Chatting" visible="true"/><rule ruleid="50093" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN用户联系人状态改变为离开" name_chs="即时通信软件MSN用户联系人状态改变为离开" name_eng="Instant Messaging Software MSN User Contact State Changed into &quot;Leave&quot;" visible="true"/><rule ruleid="50092" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN用户状态改变为离开" name_chs="即时通信软件MSN用户状态改变为离开" name_eng="Instant Messaging Software MSN User State Changed into &quot;Leave&quot;" visible="true"/><rule ruleid="50091" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN传送文件失败" name_chs="即时通信软件MSN传送文件失败" name_eng="Instant Messaging Software MSN Sending Files Failed" visible="true"/><rule ruleid="50090" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN传送文件成功" name_chs="即时通信软件MSN传送文件成功" name_eng="Instant Messaging Software MSN Sending Files Succeeded" visible="true"/><rule ruleid="10143" enabled="true" group="368052246" action=" db  screen " name="Apple Mac OS X AppleFileServer FPLoginExt远程拒绝服务攻击" name_chs="Apple Mac OS X AppleFileServer FPLoginExt远程拒绝服务攻击" name_eng="Apple Mac OS X AppleFileServer FPLoginExt Remote Denial of Service" visible="true"/><rule ruleid="20508" enabled="true" group="203423919" action=" db  screen " name="phpBB highlight变量远程任意命令执行攻击" name_chs="phpBB highlight变量远程任意命令执行攻击" name_eng="phpBB highlight Variable Remote Arbitrary Command Execution" visible="true"/><rule ruleid="50039" enabled="false" group="72613967" action=" db  screen " name="POP3服务接收.vbs病毒邮件" name_chs="POP3服务接收.vbs病毒邮件" name_eng="POP3 Service Receiving Mails with .vbs Virus" visible="true"/><rule ruleid="50038" enabled="true" group="209977423" action=" db  screen  drop " name="SMTP服务发送可疑病毒邮件" name_chs="SMTP服务发送可疑病毒邮件" name_eng="SMTP Service Sending Mails with Suspicious Virus" visible="true" merge="[t7200,si]"/><rule ruleid="20509" enabled="true" group="95420719" action=" db  screen " name="Microsoft Windows入站SMB报文验证远程溢出攻击" name_chs="Microsoft Windows入站SMB报文验证远程溢出攻击" name_eng="Microsoft Windows Inbound SMB Message Authentication Remote Buffer Overflow" visible="true"/><rule ruleid="50031" enabled="true" group="204537949" action=" db  screen " name="FTP服务普通用户认证" name_chs="FTP服务普通用户认证" name_eng="FTP Service Unprivileged User Authentication" visible="true" merge="[t7200,si,di]"/><rule ruleid="50030" enabled="true" group="99618895" action=" db  screen " name="DameWare远程控制软件建立连接" name_chs="DameWare远程控制软件建立连接" name_eng="Remote Control Software DameWare Connection" visible="true"/><rule ruleid="50032" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Worm.MiMail蠕虫病毒邮件" name_chs="SMTP服务发送Worm.MiMail蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Worm.MiMail" visible="true"/><rule ruleid="50035" enabled="true" group="210829401" action=" db  screen " name="IMAP服务用户认证" name_chs="IMAP服务用户认证" name_eng="IMAP Service User Authentication" visible="true"/><rule ruleid="50037" enabled="true" group="209977423" action=" db  screen  drop " name="SMTP服务发送.vbs病毒邮件" name_chs="SMTP服务发送.vbs病毒邮件" name_eng="SMTP Service Sending Mails with .vbs Virus" visible="true"/><rule ruleid="50036" enabled="true" group="210829401" action=" db  screen " name="IMAP服务用户认证" name_chs="IMAP服务用户认证" name_eng="IMAP Service User Authentication" visible="true"/><rule ruleid="50088" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN用户下线" name_chs="即时通信软件MSN用户下线" name_eng="Instant Messaging Software MSN User Offline" visible="true"/><rule ruleid="20502" enabled="true" group="203423919" action=" db  screen " name="PostNuke readmsg.php CGI脚本SQL注入攻击" name_chs="PostNuke readmsg.php CGI脚本SQL注入攻击" name_eng="PostNuke readmsg.php CGI Script SQL Injection" visible="true"/><rule ruleid="20503" enabled="true" group="203423919" action=" db  screen " name="OpenBB read.php CGI脚本SQL注入攻击" name_chs="OpenBB read.php CGI脚本SQL注入攻击" name_eng="OpenBB read.php CGI Script SQL Injection" visible="true"/><rule ruleid="20500" enabled="true" group="203423918" action=" db  screen " name="phpBB bbcode.php CGI脚本跨站脚本执行攻击" name_chs="phpBB bbcode.php CGI脚本跨站脚本执行攻击" name_eng="phpBB bbcode.php CGI Cross-Site Scripting" visible="true"/><rule ruleid="10120" enabled="true" group="233834527" action=" db  screen  drop " name="UDP畸形数据包拒绝服务攻击" name_chs="UDP畸形数据包拒绝服务攻击" name_eng="Malformed UDP Packet Denial of Service" visible="true"/><rule ruleid="20506" enabled="true" group="143655211" action=" db  screen " name="GNU Mailutils 0.6 imap4d TAG格式串溢出攻击" name_chs="GNU Mailutils 0.6 imap4d TAG格式串溢出攻击" name_eng="GNU Mailutils 0.6 imap4d TAG Format String Buffer Overflow" visible="true"/><rule ruleid="20507" enabled="true" group="203423919" action=" db  screen " name="Mambo com_content模块user_rating远程SQL注入漏洞" name_chs="Mambo com_content模块user_rating远程SQL注入漏洞" name_eng="Mambo com_content Module user_rating Remote SQL Injection" visible="true"/><rule ruleid="50145" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具KuGoo文件下载" name_chs="P2P文件共享工具KuGoo文件下载" name_eng="P2P File Sharing Tool KuGoo File Downloading" visible="true"/><rule ruleid="50144" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具百宝文件下载" name_chs="P2P文件共享工具百宝文件下载" name_eng="P2P File Sharing Tool 100bao File Downloading" visible="true"/><rule ruleid="50147" enabled="true" group="368115781" action=" db  screen " name="DB2数据库管理服务回应" name_chs="DB2数据库管理服务回应" name_eng="DB2 Database Management Service Response" visible="true"/><rule ruleid="50146" enabled="true" group="233963613" action=" db  screen " name="P2P文件共享工具天网Maze文件下载" name_chs="P2P文件共享工具天网Maze文件下载" name_eng="P2P File Sharing Tool Maze File Downloading" visible="true"/><rule ruleid="50141" enabled="true" group="233963613" action=" db  screen " name="PPStream网络电视流媒体播放" name_chs="PPStream网络电视流媒体播放" name_eng="PPStream Network TV Streaming Media Playing" visible="true"/><rule ruleid="20504" enabled="true" group="203423919" action=" db  screen " name="Qualiteam X-Cart giftcert.php CGI脚本SQL注入攻击" name_chs="Qualiteam X-Cart giftcert.php CGI脚本SQL注入攻击" name_eng="Qualiteam X-Cart giftcert.php CGI Script SQL Injection" visible="true"/><rule ruleid="50143" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具迅雷文件下载(TCP)" name_chs="P2P文件共享工具迅雷文件下载(TCP)" name_eng="P2P File Sharing Tool Xunlei File Downloading (TCP)" visible="true"/><rule ruleid="50142" enabled="true" group="233963613" action=" db  screen " name="沸点网络电视流媒体播放" name_chs="沸点网络电视流媒体播放" name_eng="feidian Network TV Streaming Media Playing" visible="true"/><rule ruleid="20505" enabled="true" group="76546347" action=" db  screen " name="Ipswitch IMAP超长LOGIN命令参数缓冲区溢出攻击" name_chs="Ipswitch IMAP超长LOGIN命令参数缓冲区溢出攻击" name_eng="Ipswitch IMAP Over-long LOGIN Command Buffer Overflow" visible="true"/><rule ruleid="50149" enabled="true" group="233963613" action=" db  screen " name="QQ直播流媒体播放" name_chs="QQ直播流媒体播放" name_eng="QQ Live Streaming Media Playing" visible="true"/><rule ruleid="50148" enabled="true" group="233963613" action=" db  screen " name="猫扑网络电视流媒体播放" name_chs="猫扑网络电视流媒体播放" name_eng="mop Network TV Streaming Media Playing" visible="true"/><rule ruleid="10147" enabled="true" group="71305242" action=" db  screen " name="Microsoft Windows 2000 telnet服务器远程拒绝服务攻击" name_chs="Microsoft Windows 2000 telnet服务器远程拒绝服务攻击" name_eng="Microsoft Windows 2000 telnet Server Remote Denial of Service" visible="true"/><rule ruleid="79999" enabled="true" group="368115781" action=" db  screen " name="内部调试事件" name_chs="内部调试事件" name_eng="Internal Debugging" visible="false"/><rule ruleid="40053" enabled="true" group="99615310" action=" db  screen " name="Windows系统远程管理工具PcAnywhere远程登录失败" name_chs="Windows系统远程管理工具PcAnywhere远程登录失败" name_eng="Windows Remote Management Tool PcAnywhere Remote Login Failed" visible="true"/><rule ruleid="40329" enabled="true" group="99618895" action=" db  screen " name="Windows系统下NCX木马连接建立" name_chs="Windows系统下NCX木马连接建立" name_eng="Trojan NCX Connection on Windows" visible="true"/><rule ruleid="70091" enabled="true" group="233865293" action="" name="RealVNC客户端发送空认证类型" name_chs="RealVNC客户端发送空认证类型" name_eng="RealVNC Client Sending NULL Authenticaition Type " visible="false"/><rule ruleid="20849" enabled="true" group="76546346" action=" db  screen " name="IMAP服务器APPEND命令超长参数缓冲区溢出攻击" name_chs="IMAP服务器APPEND命令超长参数缓冲区溢出攻击" name_eng="IMAP Server APPEND Command Over-Long Parameter Buffer Overflow" visible="true"/><rule ruleid="20848" enabled="true" group="68157738" action=" db  screen " name="Mozilla Firefox Javascript导航器对象远程代码执行攻击" name_chs="Mozilla Firefox Javascript导航器对象远程代码执行攻击" name_eng="Mozilla Firefox Javascript Navigator Object Remote Code Execution" visible="true"/><rule ruleid="20843" enabled="true" group="83886378" action=" db  screen " name="CA BrightStor ARCserve Backup Tape Engine服务远程缓冲区溢出攻击" name_chs="CA BrightStor ARCserve Backup Tape Engine服务远程缓冲区溢出攻击" name_eng="CA BrightStor ARCserve Backup Tape Engine Service Buffer Overflow" visible="true"/><rule ruleid="20842" enabled="true" group="83886378" action=" db  screen " name="CA BrightStor ARCserve Message Engine服务远程堆溢出攻击" name_chs="CA BrightStor ARCserve Message Engine服务远程堆溢出攻击" name_eng="CA BrightStor ARCserve Message Engine Service Remote Heap Overflow" visible="true"/><rule ruleid="20841" enabled="true" group="83886378" action=" db  screen " name="CA BrightStor ARCServe BackUp Message/Tape Engine服务远程溢出攻击" name_chs="CA BrightStor ARCServe BackUp Message/Tape Engine服务远程溢出攻击" name_eng="CA BrightStor ARCServe BackUp Message/Tape Engine Service Remote Buffer Overflow" visible="true"/><rule ruleid="20840" enabled="true" group="99615018" action=" db  screen " name="Mercury/32 PH Server模块远程缓冲区溢出攻击" name_chs="Mercury/32 PH Server模块远程缓冲区溢出攻击" name_eng="Mercury/32 PH Server Module Remote Buffer Overflow" visible="true"/><rule ruleid="20847" enabled="true" group="68157738" action=" db  screen " name="NaviCOPA Web Server远程缓冲区溢出攻击" name_chs="NaviCOPA Web Server远程缓冲区溢出攻击" name_eng="NaviCOPA Web Server Remote Buffer Overflow" visible="true"/><rule ruleid="20846" enabled="true" group="68157738" action=" db  screen " name="Mozilla Suite/Firefox compareTo()代码执行攻击" name_chs="Mozilla Suite/Firefox compareTo()代码执行攻击" name_eng="Mozilla Suite/Firefox compareTo() Code Execution" visible="true"/><rule ruleid="20845" enabled="true" group="68157738" action=" db  screen " name="HTTP协议URL字段超长缓冲区溢出攻击" name_chs="HTTP协议URL字段超长缓冲区溢出攻击" name_eng="HTTP Protocol Over-Long URL Field Buffer Overflow" visible="true"/><rule ruleid="20844" enabled="true" group="83886378" action=" db  screen " name="CA BrightStor ARCserve Backup Media Server组件远程栈溢出攻击" name_chs="CA BrightStor ARCserve Backup Media Server组件远程栈溢出攻击" name_eng="CA BrightStor ARCserve Backup Media Server Component Remote Stack Overflow" visible="true"/><rule ruleid="70090" enabled="true" group="233865293" action="" name="RealVNC服务端发送认证类型" name_chs="RealVNC服务端发送认证类型" name_eng="RealVNC Server Sending Authentication Type " visible="false"/><rule ruleid="20601" enabled="true" group="203423915" action=" db  screen " name="Nucleus CMS PLUGINADMIN.php远程文件包含攻击" name_chs="Nucleus CMS PLUGINADMIN.php远程文件包含攻击" name_eng="Nucleus CMS PLUGINADMIN.php Remote File Inclusion" visible="true"/><rule ruleid="20600" enabled="true" group="203423919" action=" db  screen " name="UBB.threads addpost_newpoll.php远程文件包含攻击" name_chs="UBB.threads addpost_newpoll.php远程文件包含攻击" name_eng="UBB.threads addpost_newpoll.php Remote File Inclusion" visible="true"/><rule ruleid="20603" enabled="true" group="166725675" action=" db  screen " name="HP OpenView OmniBack非授权命令执行攻击" name_chs="HP OpenView OmniBack非授权命令执行攻击" name_eng="HP OpenView OmniBack Unauthorized Code Execution" visible="true"/><rule ruleid="20602" enabled="true" group="203423915" action=" db  screen " name="DotClear prepend.php远程文件包含攻击" name_chs="DotClear prepend.php远程文件包含攻击" name_eng="DotClear prepend.php Remote File Inclusion" visible="true"/><rule ruleid="20605" enabled="true" group="203423915" action=" db  screen " name="RaXnet Cacti graph_image.php远程命令执行攻击" name_chs="RaXnet Cacti graph_image.php远程命令执行攻击" name_eng="RaXnet Cacti graph_image.php Remote Code Execution" visible="true"/><rule ruleid="20607" enabled="true" group="203423915" action=" db  screen " name="Simple PHP Blog上传脚本文件执行代码攻击" name_chs="Simple PHP Blog上传脚本文件执行代码攻击" name_eng="Simple PHP Blog Upload Script Code Execution" visible="true"/><rule ruleid="20606" enabled="true" group="69206187" action=" db  screen " name="Lyris ListManager远程命令执行攻击" name_chs="Lyris ListManager远程命令执行攻击" name_eng="Lyris ListManager Remote Code Execution" visible="true"/><rule ruleid="20609" enabled="true" group="156239915" action=" db  screen " name="Solaris LPD远程命令执行攻击" name_chs="Solaris LPD远程命令执行攻击" name_eng="Solaris LPD Remote Command Execution" visible="true"/><rule ruleid="20608" enabled="true" group="136315051" action=" db  screen " name="Barracuda img.pl远程命令执行攻击" name_chs="Barracuda img.pl远程命令执行攻击" name_eng="Barracuda img.pl Remote Code Execution" visible="true"/><rule ruleid="10070" enabled="true" group="144705567" action=" db  screen " name="ISC BIND OPT资源记录远程拒绝服务攻击" name_chs="ISC BIND OPT资源记录远程拒绝服务攻击" name_eng="ISC BIND OPT Resource Record Remote Denial of Service" visible="true"/><rule ruleid="20933" enabled="true" group="99616810" action=" db  screen " name="SynCE vdccm守护程序远程命令注入攻击" name_chs="SynCE vdccm守护程序远程命令注入攻击" name_eng="SynCE vdccm Daemon Remote Command Injection Vulnerability" visible="true"/><rule ruleid="20932" enabled="true" group="68159530" action=" db  screen " name="Gateway CWebLaunchCtl ActiveX控件远程栈溢出攻击" name_chs="Gateway CWebLaunchCtl ActiveX控件远程栈溢出攻击" name_eng="Gateway CWebLaunchCtl ActiveX Control Remote Stack Overflow Vulnerability" visible="true"/><rule ruleid="20931" enabled="true" group="68157610" action=" db  screen " name="Tikiwiki CMS tiki-listmovies.php文件目录遍历攻击" name_chs="Tikiwiki CMS tiki-listmovies.php文件目录遍历攻击" name_eng="Tikiwiki CMS tiki-listmovies.php Directory Traversal Vulnerability" visible="true"/><rule ruleid="20930" enabled="true" group="68157610" action=" db  screen " name="Wordpress xmlrpc.php脚本远程SQL注入攻击" name_chs="Wordpress xmlrpc.php脚本远程SQL注入攻击" name_eng="Wordpress xmlrpc.php Script Remote SQL Injection Vulnerability" visible="true"/><rule ruleid="20937" enabled="true" group="68159530" action=" db  screen " name="Macrovision FLEXnet Connect ActiveX控件恶意文件下载攻击" name_chs="Macrovision FLEXnet Connect ActiveX控件恶意文件下载攻击" name_eng="Macrovision FLEXnet Connect ActiveX Control Malicious File Dwonloading Vulnerability" visible="true"/><rule ruleid="20935" enabled="true" group="233832746" action=" db  screen " name="yaSSL多个远程溢出及无效内存访问攻击" name_chs="yaSSL多个远程溢出及无效内存访问攻击" name_eng="yaSSL Multiple Remote Overflow and Invalid Memory Access Vulnerabilities" visible="true"/><rule ruleid="20934" enabled="true" group="166723882" action=" db  screen " name="CUPS SNMP后端asn1_get_string()函数远程栈溢出攻击" name_chs="CUPS SNMP后端asn1_get_string()函数远程栈溢出攻击" name_eng="CUPS SNMP后端asn1_get_string() Function Remote Stack Overflow Vulnerability" visible="true"/><rule ruleid="20939" enabled="true" group="68157738" action=" db  screen " name="CA ETrust Intrusion Detection Caller.dll控件远程代码执行攻击" name_chs="CA ETrust Intrusion Detection Caller.dll控件远程代码执行攻击" name_eng="CA ETrust Intrusion Detection Caller.dll Control Remote Code Execution Vulnerability" visible="true"/><rule ruleid="20938" enabled="true" group="99616810" action=" db  screen " name="SAP MaxDB cons.exe远程命令注入攻击" name_chs="SAP MaxDB cons.exe远程命令注入攻击" name_eng="SAP MaxDB cons.exe Remote Command Injection Vulnerability" visible="true"/><rule ruleid="20118" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.cmsd远程缓冲区溢出攻击" name_chs="Solaris rpc.cmsd远程缓冲区溢出攻击" name_eng="Solaris rpc.cmsd Remote Buffer Overflow" visible="true"/><rule ruleid="20115" enabled="true" group="150995247" action=" db  screen " name="Linux rpc.statd远程格式串TCP溢出攻击" name_chs="Linux rpc.statd远程格式串TCP溢出攻击" name_eng="Linux rpc.statd Remote Format String TCP Overflow" visible="true"/><rule ruleid="20111" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.yppasswdd远程缓冲区溢出攻击" name_chs="Solaris rpc.yppasswdd远程缓冲区溢出攻击" name_eng="Solaris rpc.yppasswdd Remote Buffer Overflow" visible="true"/><rule ruleid="20110" enabled="true" group="227541295" action=" db  screen " name="SNMPv1请求处理远程缓冲区溢出攻击" name_chs="SNMPv1请求处理远程缓冲区溢出攻击" name_eng="SNMPv1 Request Processing Remote Buffer Overflow" visible="true"/><rule ruleid="20113" enabled="true" group="150995247" action=" db  screen " name="Linux rpc.statd远程格式串UDP溢出攻击" name_chs="Linux rpc.statd远程格式串UDP溢出攻击" name_eng="Linux rpc.statd Remote Format String UDP Overflow" visible="true"/><rule ruleid="20591" enabled="true" group="203423919" action=" db  screen " name="AwStats migrate参数远程执行命令攻击" name_chs="AwStats migrate参数远程执行命令攻击" name_eng="AwStats migrate Parameter Remomte Code Execution" visible="true"/><rule ruleid="20590" enabled="true" group="203423919" action=" db  screen " name="TopList Hack for phpBB远程文件包含攻击" name_chs="TopList Hack for phpBB远程文件包含攻击" name_eng="TopList Hack for phpBB Remote File Inclusion" visible="true"/><rule ruleid="20593" enabled="true" group="69206315" action=" db  screen " name="MySQL MaxDB HTTP GET请求远程缓冲区溢出攻击" name_chs="MySQL MaxDB HTTP GET请求远程缓冲区溢出攻击" name_eng="MySQL MaxDB HTTP GET Request Remote Buffer Overflow" visible="true"/><rule ruleid="20592" enabled="true" group="233832747" action=" db  screen " name="Epic Games Unreal Engine Secure Query缓冲区溢出攻击" name_chs="Epic Games Unreal Engine Secure Query缓冲区溢出攻击" name_eng="Epic Games Unreal Engine Secure Query Buffer Overflow" visible="true"/><rule ruleid="20595" enabled="true" group="99615019" action=" db  screen " name="Veritas Backup Exec注册请求远程缓冲区溢出攻击" name_chs="Veritas Backup Exec注册请求远程缓冲区溢出攻击" name_eng="Veritas Backup Exec Register Request Remote Buffer Overflow" visible="true"/><rule ruleid="20594" enabled="true" group="69206315" action=" db  screen " name="Microsoft IIS w3who ISAPI DLL远程缓冲区溢出攻击" name_chs="Microsoft IIS w3who ISAPI DLL远程缓冲区溢出攻击" name_eng="Microsoft IIS w3who ISAPI DLL Remote Buffer Overflow" visible="true"/><rule ruleid="20597" enabled="true" group="233832747" action=" db  screen " name="Arkeia Server Backup 77请求类型远程缓冲区溢出攻击" name_chs="Arkeia Server Backup 77请求类型远程缓冲区溢出攻击" name_eng="Arkeia Server Backup Type 77 Request Remote Buffer Overflow" visible="true"/><rule ruleid="20596" enabled="true" group="99615019" action=" db  screen " name="ISS RealSecure/BlackICE协议分析模块ICQ应答处理缓冲区攻击" name_chs="ISS RealSecure/BlackICE协议分析模块ICQ应答处理缓冲区攻击" name_eng="ISS RealSecure/BlackICE Protocol Analysis Module ICQ Response Handling Buffer Overflow" visible="true"/><rule ruleid="20599" enabled="true" group="203423915" action=" db  screen " name="phpListPro returnpath变量远程文件包含攻击" name_chs="phpListPro returnpath变量远程文件包含攻击" name_eng="phpListPro returnpath Variable Remote File Inclusion" visible="true"/><rule ruleid="20598" enabled="true" group="99615019" action=" db  screen " name="AOL Instant Messenger Away Message缓冲区溢出攻击" name_chs="AOL Instant Messenger Away Message缓冲区溢出攻击" name_eng="AOL Instant Messenger Away Message Buffer Overflow" visible="true"/><rule ruleid="30175" enabled="true" group="136315066" action=" db  screen " name="Microsoft FrontPage administrators.pwd文件访问" name_chs="Microsoft FrontPage administrators.pwd文件访问" name_eng="Access to Microsoft FrontPage administrators.pwd File" visible="true"/><rule ruleid="40048" enabled="true" group="204537950" action=" db  screen " name="FTP服务普通用户认证" name_chs="FTP服务普通用户认证" name_eng="FTP Service Unprivileged User Authentication" visible="true"/><rule ruleid="30178" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp2.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp2.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp2.htr File" visible="true"/><rule ruleid="30179" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp2b.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp2b.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp2b.htr File" visible="true"/><rule ruleid="30176" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/achg.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/achg.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/achg.htr File" visible="true"/><rule ruleid="30177" enabled="true" group="69206202" action=" db  screen " name="Microsoft IIS 4.0 /iisadmpwd/aexp.htr文件访问" name_chs="Microsoft IIS 4.0 /iisadmpwd/aexp.htr文件访问" name_eng="Access to Microsoft IIS 4.0 /iisadmpwd/aexp.htr File" visible="true"/><rule ruleid="30174" enabled="true" group="136315066" action=" db  screen " name="Microsoft FrontPage authors.pwd文件访问" name_chs="Microsoft FrontPage authors.pwd文件访问" name_eng="Access to Microsoft FrontPage authors.pwd File" visible="true"/><rule ruleid="40046" enabled="true" group="137365547" action=" db  screen  drop " name="FTP服务SITE EXEC执行命令攻击" name_chs="FTP服务SITE EXEC执行命令攻击" name_eng="FTP Service SITE EXEC Command Execution" visible="true"/><rule ruleid="30172" enabled="true" group="136315066" action=" db  screen " name="访问Microsoft FrontPage扩展users.pwd文件" name_chs="访问Microsoft FrontPage扩展users.pwd文件" name_eng="Access to Microsoft FrontPage Extension users.pwd File" visible="true"/><rule ruleid="30173" enabled="true" group="136315066" action=" db  screen " name="访问Microsoft FrontPage扩展service.pwd文件" name_chs="访问Microsoft FrontPage扩展service.pwd文件" name_eng="Access to Microsoft FrontPage Extension service.pwd File" visible="true"/><rule ruleid="40042" enabled="true" group="204537942" action=" db  screen " name="FTP服务客户端CWD ~root操作" name_chs="FTP服务客户端CWD ~root操作" name_eng="FTP Service Client End CWD ~root Operation" visible="true"/><rule ruleid="30171" enabled="true" group="69206203" action=" db  screen " name="通过Web服务访问Windows 2000的SAM文件" name_chs="通过Web服务访问Windows 2000的SAM文件" name_eng="Access to SAM File of Windows 2000 via Web Service" visible="true"/><rule ruleid="30527" enabled="false" group="141566013" action=" db  screen " name="SSH服务返回版本信息" name_chs="SSH服务返回版本信息" name_eng="SSH Service Returning Version Information" visible="true"/><rule ruleid="20029" enabled="true" group="144703791" action=" db  screen " name="针对BIND服务的远程溢出攻击" name_chs="针对BIND服务的远程溢出攻击" name_eng="Remote Buffer Overflow on BIND Service" visible="true"/><rule ruleid="20021" enabled="true" group="142606631" action=" db  screen " name="NetManage Chameleon SMTP服务远程缓冲区溢出攻击" name_chs="NetManage Chameleon SMTP服务远程缓冲区溢出攻击" name_eng="NetManage Chameleon SMTP Service Remote Buffer Overflow" visible="true"/><rule ruleid="40136" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Progenic木马通信" name_chs="Windows系统下Progenic木马通信" name_eng="Trojan Progenic Communication on Windows" visible="true"/><rule ruleid="20344" enabled="true" group="68157743" action=" db  screen  drop " name="Microsoft IIS 5.0 WebDAV远程缓冲区溢出攻击" name_chs="Microsoft IIS 5.0 WebDAV远程缓冲区溢出攻击" name_eng="Microsoft IIS 5.0 WebDAV Remote Buffer Overflow" visible="true"/><rule ruleid="30526" enabled="true" group="136315066" action=" db  screen " name="利用Big Brother bb-hist.sh脚本漏洞遍历主机目录" name_chs="利用Big Brother bb-hist.sh脚本漏洞遍历主机目录" name_eng="Remote Host Directory Traversal via Big Brother bb-hist.sh Script Vulnerability" visible="true"/><rule ruleid="40268" enabled="true" group="69214269" action=" db  screen " name="Microsoft IIS bdir.htr脚本漏洞扫描探测" name_chs="Microsoft IIS bdir.htr脚本漏洞扫描探测" name_eng="Microsoft IIS bdir.htr Script Vulnerability Detection" visible="true"/><rule ruleid="40599" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Uploader木马通信" name_chs="Windows系统下Uploader木马通信" name_eng="Trojan Uploader Communication on Windows" visible="true"/><rule ruleid="40598" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Undetected木马通信" name_chs="Windows系统下Undetected木马通信" name_eng="Trojan Undetected Communication on Windows" visible="true"/><rule ruleid="20346" enabled="true" group="160464970" action=" db  screen " name="Solaris SNMP默认共同体串访问" name_chs="Solaris SNMP默认共同体串访问" name_eng="Solaris SNMP Default Community String" visible="true"/><rule ruleid="40593" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Tron木马通信" name_chs="Windows系统下Tron木马通信" name_eng="Trojan Tron Communication on Windows" visible="true"/><rule ruleid="40592" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Trojan Spirit木马通信" name_chs="Windows系统下Trojan Spirit木马通信" name_eng="Trojan Trojan Spirit Communication on Windows" visible="true"/><rule ruleid="40591" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Trojan Cow木马通信" name_chs="Windows系统下Trojan Cow木马通信" name_eng="Trojan Trojan Cow Communication on Windows" visible="true"/><rule ruleid="40590" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Transmission Scout木马通信" name_chs="Windows系统下Transmission Scout木马通信" name_eng="Trojan Transmission Scout Communication on Windows" visible="true"/><rule ruleid="40597" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Ultors木马通信" name_chs="Windows系统下Ultors木马通信" name_eng="Trojan Ultors Communication on Windows" visible="true"/><rule ruleid="40596" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下UltimateRAT木马通信" name_chs="Windows系统下UltimateRAT木马通信" name_eng="Trojan UltimateRAT Communication on Windows" visible="true"/><rule ruleid="40595" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Ullysse木马通信" name_chs="Windows系统下Ullysse木马通信" name_eng="Trojan Ullysse Communication on Windows" visible="true"/><rule ruleid="40594" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Truva木马通信" name_chs="Windows系统下Truva木马通信" name_eng="Trojan Truva Communication on Windows" visible="true"/><rule ruleid="50202" enabled="true" group="68223069" action=" db  screen " name="Baidu网络爬虫抓取网页信息" name_chs="Baidu网络爬虫抓取网页信息" name_eng="Baidu Web Crawlers Capture Page Information" visible="true"/><rule ruleid="50203" enabled="true" group="68223069" action=" db  screen " name="iAsk网络爬虫抓取网页信息" name_chs="iAsk网络爬虫抓取网页信息" name_eng="iAsk Web Crawlers Capture Page Information" visible="true"/><rule ruleid="50200" enabled="true" group="68288605" action=" db  screen " name="P2P文件共享工具迅雷获取多点下载地址信息" name_chs="P2P文件共享工具迅雷获取多点下载地址信息" name_eng="P2P File Sharing Tool Xunlei Obtaining Multi-Point Download Address Information" visible="true"/><rule ruleid="50201" enabled="false" group="99680345" action=" db  screen " name="网络代理软件自由门数据通信" name_chs="网络代理软件自由门数据通信" name_eng="Network Agent Software Freedoor Data Communication" visible="false"/><rule ruleid="50206" enabled="true" group="99745881" action=" db  screen " name="即时通信软件QQ文件传输(UDP)" name_chs="即时通信软件QQ文件传输(UDP)" name_eng="Instant Messaging Software QQ File Transmission (UDP)" visible="true"/><rule ruleid="50207" enabled="true" group="233963609" action=" db  screen " name="网络代理软件数据通信(UDP)" name_chs="网络代理软件数据通信(UDP)" name_eng="Network Agent Software Data Communication (UDP)" visible="true"/><rule ruleid="50204" enabled="true" group="68223069" action=" db  screen " name="股票行情分析操作软件申银万国神网E通用户登录" name_chs="股票行情分析操作软件申银万国神网E通用户登录" name_eng="Stock Market Analysis Software sw2000.com.cn User Login" visible="true"/><rule ruleid="50205" enabled="true" group="233963609" action=" db  screen " name="网络代理软件数据通信(TCP)" name_chs="网络代理软件数据通信(TCP)" name_eng="Network Agent Software Data Communication (TCP)" visible="true"/><rule ruleid="50208" enabled="true" group="233963613" action=" db  screen " name="土豆网在线流媒体播放" name_chs="土豆网在线流媒体播放" name_eng="Tudou.com Online Streaming Media Playing" visible="true"/><rule ruleid="50209" enabled="true" group="233963613" action=" db  screen " name="酷6网在线流媒体播放" name_chs="酷6网在线流媒体播放" name_eng="ku6.com Online Streaming Media Playing" visible="true"/><rule ruleid="30378" enabled="true" group="135266494" action=" db  screen " name="通过Web服务访问.htpasswd文件" name_chs="通过Web服务访问.htpasswd文件" name_eng="Access to .htpasswd File via Web Service" visible="true"/><rule ruleid="30379" enabled="true" group="69206202" action=" db  screen " name="Oracle Web Listener批处理漏洞远程执行命令扫描利用" name_chs="Oracle Web Listener批处理漏洞远程执行命令扫描利用" name_eng="Oracle Web Listener Batch Vulnerability Remote Code Execution Detection" visible="true"/><rule ruleid="20864" enabled="true" group="99615018" action=" db  screen " name="eIQnetworks Enterprise Security Analyzer拓扑服务器栈溢出攻击" name_chs="eIQnetworks Enterprise Security Analyzer拓扑服务器栈溢出攻击" name_eng="eIQnetworks Enterprise Security Analyzer Topology Server Stack Overflow" visible="true"/><rule ruleid="30370" enabled="true" group="136315062" action=" db  screen " name="扫描探测Sojourn sojourn.cgi脚本漏洞" name_chs="扫描探测Sojourn sojourn.cgi脚本漏洞" name_eng="Sojourn sojourn.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30371" enabled="true" group="136315066" action=" db  screen " name="利用ROADS search.pl CGI漏洞远程察看系统文件" name_chs="利用ROADS search.pl CGI漏洞远程察看系统文件" name_eng="System File Disclosure via ROADS search.pl CGI Vulnerability" visible="true"/><rule ruleid="30372" enabled="true" group="136315066" action=" db  screen " name="search.pl脚本漏洞扫描探测" name_chs="search.pl脚本漏洞扫描探测" name_eng="search.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30373" enabled="true" group="337649718" action=" db  screen " name="3COM OfficeConnect Router Web管理接口漏洞扫描探测" name_chs="3COM OfficeConnect Router Web管理接口漏洞扫描探测" name_eng="3COM OfficeConnect Router Web Management Interface Vulnerability Detection" visible="true"/><rule ruleid="30374" enabled="true" group="136315066" action=" db  screen " name="Big Brother bb-rep.sh脚本漏洞扫描利用" name_chs="Big Brother bb-rep.sh脚本漏洞扫描利用" name_eng="Big Brother bb-rep.sh Script Vulnerability Detection" visible="true"/><rule ruleid="30375" enabled="true" group="136315066" action=" db  screen " name="Big Brother bb-replog.sh脚本漏洞扫描利用" name_chs="Big Brother bb-replog.sh脚本漏洞扫描利用" name_eng="Big Brother bb-replog.sh Script Vulnerability Detection" visible="true"/><rule ruleid="40681" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AZ@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AZ@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AZ@mm" visible="true"/><rule ruleid="40680" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Salga.B蠕虫病毒邮件" name_chs="SMTP服务发送W32.Salga.B蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Salga.B" visible="true"/><rule ruleid="40467" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Remote Revise木马通信" name_chs="Windows系统下Remote Revise木马通信" name_eng="Trojan Remote Revise Communication on Windows" visible="true"/><rule ruleid="40466" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Net Devil木马通信" name_chs="Windows系统下Net Devil木马通信" name_eng="Trojan Net Devil Communication on Windows" visible="true"/><rule ruleid="20866" enabled="true" group="69206186" action=" db  screen " name="vBulletin misc.php template名远程代码注入攻击" name_chs="vBulletin misc.php template名远程代码注入攻击" name_eng="vBulletin misc.php template Remote Code Injection" visible="true"/><rule ruleid="20142" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序rksh" name_chs="通过Web服务访问Unix Shell解释程序rksh" name_eng="Access to Unix Shell Interpreter rksh via Web Service" visible="true"/><rule ruleid="30000" enabled="true" group="136315062" action=" db  screen " name="Unix Manual manual.php脚本漏洞扫描利用" name_chs="Unix Manual manual.php脚本漏洞扫描利用" name_eng="Unix Manual manual.php Script Vulnerability Detection" visible="true"/><rule ruleid="20861" enabled="true" group="99615018" action=" db  screen " name="UltraVNC客户端缓冲区溢出攻击" name_chs="UltraVNC客户端缓冲区溢出攻击" name_eng="UltraVNC Client Buffer Overflow" visible="true"/><rule ruleid="40469" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Alvgus木马通信" name_chs="Windows系统下Alvgus木马通信" name_eng="Trojan Alvgus Communication on Windows" visible="true"/><rule ruleid="40468" enabled="true" group="69206223" action=" db  screen " name="通过Web服务执行root.exe程序" name_chs="通过Web服务执行root.exe程序" name_eng="root.exe Program Execution via Web Service" visible="true"/><rule ruleid="30396" enabled="true" group="203423930" action=" db  screen " name="Allaire Forums GetFile.cfm脚本漏洞扫描探测" name_chs="Allaire Forums GetFile.cfm脚本漏洞扫描探测" name_eng="Allaire Forums GetFile.cfm Script Vulnerability Detection" visible="true"/><rule ruleid="30397" enabled="true" group="136323130" action=" db  screen " name="NETCODE book.cgi脚本漏洞扫描探测" name_chs="NETCODE book.cgi脚本漏洞扫描探测" name_eng="NETCODE book.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30394" enabled="true" group="136315062" action=" db  screen " name="利用AlienForm2 af.cgi脚本漏洞遍历目录" name_chs="利用AlienForm2 af.cgi脚本漏洞遍历目录" name_eng="Directory Traversal via AlienForm2 af.cgi Script Vulnerability" visible="true"/><rule ruleid="30395" enabled="true" group="203423930" action=" db  screen " name="利用Allaire Forums GetFile.cfm远程读取文件" name_chs="利用Allaire Forums GetFile.cfm远程读取文件" name_eng="Remote File Reading via Allaire Forums GetFile.cfm" visible="true"/><rule ruleid="30392" enabled="true" group="203431994" action=" db  screen " name="Cart32 c32web.exe脚本漏洞扫描探测" name_chs="Cart32 c32web.exe脚本漏洞扫描探测" name_eng="Cart32 c32web.exe Script Vulnerability Detection" visible="true"/><rule ruleid="30393" enabled="true" group="136315062" action=" db  screen " name="利用AlienForm2 alienform.cgi脚本漏洞遍历目录" name_chs="利用AlienForm2 alienform.cgi脚本漏洞遍历目录" name_eng="Directory Traversal via AlienForm2 alienform.cgi Script Vulnerability" visible="true"/><rule ruleid="40663" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Yanz.B蠕虫病毒邮件" name_chs="SMTP服务发送W32.Yanz.B蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Yanz.B" visible="true"/><rule ruleid="40662" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Sober.I@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Sober.I@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Sober.I@mm" visible="true"/><rule ruleid="20862" enabled="true" group="69206186" action=" db  screen " name="WordPress cache_lastpostdate远程命令执行攻击" name_chs="WordPress cache_lastpostdate远程命令执行攻击" name_eng="WordPress cache_lastpostdate Remote Command Execution" visible="true"/><rule ruleid="40669" enabled="true" group="75759691" action=" db  screen " name="SMTP服务发送W32.Maslan.A蠕虫病毒邮件" name_chs="SMTP服务发送W32.Maslan.A蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Maslan.A" visible="true"/><rule ruleid="40668" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Mugly蠕虫病毒邮件" name_chs="SMTP服务发送W32.Mugly蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Mugly" visible="true"/><rule ruleid="30398" enabled="true" group="203423926" action=" db  screen " name="利用phpinfo.php脚本漏洞收集系统信息" name_chs="利用phpinfo.php脚本漏洞收集系统信息" name_eng="System Information Disclosure via phpinfo.php Script Vulnerability" visible="true"/><rule ruleid="50022" enabled="true" group="99647577" action=" db  screen " name="WinGate FTP代理服务开放" name_chs="WinGate FTP代理服务开放" name_eng="WinGate FTP Proxy Service Open" visible="true"/><rule ruleid="50023" enabled="true" group="72417369" action=" db  screen " name="WinGate POP3代理服务开放" name_chs="WinGate POP3代理服务开放" name_eng="WinGate POP3 Proxy Service Open" visible="true"/><rule ruleid="50024" enabled="true" group="73401422" action=" db  screen " name="Windows系统下W32.Opaserv蠕虫及其变种扫描活动" name_chs="Windows系统下W32.Opaserv蠕虫及其变种扫描活动" name_eng="W32.Opaserv and Variant Scanning on Windows" visible="true" merge="[t7200,si]"/><rule ruleid="40032" enabled="true" group="146808889" action=" db  screen " name="FINGER服务请求数字用户获取列表攻击" name_chs="FINGER服务请求数字用户获取列表攻击" name_eng="List Disclosure to Users with Numeric Usernames via FINGER Request" visible="true"/><rule ruleid="40034" enabled="true" group="146808889" action=" db  screen " name="FINGER服务“;”请求执行命令攻击" name_chs="FINGER服务“;”请求执行命令攻击" name_eng="FINGER Service &quot;;&quot; Request Command Execution" visible="true"/><rule ruleid="40035" enabled="true" group="146808889" action=" db  screen " name="FINGER服务探测NULL用户攻击" name_chs="FINGER服务探测NULL用户攻击" name_eng="FINGER Service NULL User Detection" visible="true"/><rule ruleid="50156" enabled="true" group="205586526" action=" db  screen " name="TELNET服务IRIX默认内置帐号登录" name_chs="TELNET服务IRIX默认内置帐号登录" name_eng="TELNET Service IRIX Default Built-in Account Login" visible="true"/><rule ruleid="50157" enabled="true" group="138477661" action=" db  screen " name="BSD Telnet服务器获取客户端信息" name_chs="BSD Telnet服务器获取客户端信息" name_eng="BSD Telnet Server Client Information Disclosure" visible="true"/><rule ruleid="50154" enabled="true" group="99745885" action=" db  screen " name="网络游戏平台黄金岛登录" name_chs="网络游戏平台黄金岛登录" name_eng="Online Game Platform &quot;Treasure Island&quot; Login" visible="true"/><rule ruleid="50155" enabled="true" group="99745885" action=" db  screen " name="即时通信软件QQ文件传输(TCP)" name_chs="即时通信软件QQ文件传输(TCP)" name_eng="Instant Messaging Software QQ File Transmission (TCP)" visible="true"/><rule ruleid="50152" enabled="true" group="233898077" action=" db  screen " name="SOCKS代理访问操作" name_chs="SOCKS代理访问操作" name_eng="SOCKS Agent Access Operation" visible="true"/><rule ruleid="30475" enabled="true" group="146802742" action=" db  screen " name="FINGER服务请求安全敏感文件攻击" name_chs="FINGER服务请求安全敏感文件攻击" name_eng="FINGER Service Secure Sensitive File Request" visible="true"/><rule ruleid="50150" enabled="true" group="233963613" action=" db  screen " name="TVAnts电视蚂蚁流媒体播放" name_chs="TVAnts电视蚂蚁流媒体播放" name_eng="TVAnts Streaming Media Playing" visible="true"/><rule ruleid="50151" enabled="true" group="233963613" action=" db  screen " name="TVKoo网络电视流媒体播放" name_chs="TVKoo网络电视流媒体播放" name_eng="TVKoo Netwoek TV Streaming Media Playing" visible="true"/><rule ruleid="30474" enabled="true" group="83894333" action=" db  screen " name="Windows RPC DCOM接口长主机名溢出漏洞扫描" name_chs="Windows RPC DCOM接口长主机名溢出漏洞扫描" name_eng="Windows RPC DCOM Interface Long Host Name Buffer Overflow Detection" visible="true"/><rule ruleid="50158" enabled="true" group="138477662" action=" db  screen " name="Telnet服务IAC选项炸弹攻击" name_chs="Telnet服务IAC选项炸弹攻击" name_eng="Telnet Service IAC Option Bomb" visible="true"/><rule ruleid="50159" enabled="true" group="99745885" action=" db  screen " name="即时通信软件AimExpress启动操作" name_chs="即时通信软件AimExpress启动操作" name_eng="Instant Messaging Software AimExpress Launching" visible="true"/><rule ruleid="40347" enabled="true" group="69206222" action=" db  screen " name="利用.&quot;./字串突破CGI脚本过滤访问上级目录" name_chs="利用.&quot;./字串突破CGI脚本过滤访问上级目录" name_eng="CGI Script Filter Bypass And Upper Directory Access via .&quot;./ String" visible="true"/><rule ruleid="10131" enabled="true" group="76548123" action=" db  screen " name="IMAP服务器SELECT命令超长参数缓冲区溢出攻击" name_chs="IMAP服务器SELECT命令超长参数缓冲区溢出攻击" name_eng="SELECT Command on the IMAP Server Over-long Parameter Buffer Overflow" visible="true"/><rule ruleid="40342" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下BackConstruction/Noknok木马通信" name_chs="Windows系统下BackConstruction/Noknok木马通信" name_eng="Trojan BackConstruction/Noknok Communication on Windows" visible="true"/><rule ruleid="40616" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.Q@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.Q@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.Q@mm" visible="true"/><rule ruleid="40617" enabled="true" group="95682639" action=" db  screen " name="Windows系统下Plexus蠕虫病毒通过共享传播" name_chs="Windows系统下Plexus蠕虫病毒通过共享传播" name_eng="Plexus Propagation by Sharing on Windows" visible="true"/><rule ruleid="10132" enabled="true" group="68159518" action=" db  screen " name="Microsoft IIS WebDAV超长请求远程拒绝服务攻击" name_chs="Microsoft IIS WebDAV超长请求远程拒绝服务攻击" name_eng="Microsoft IIS WebDAV Over-long Request Remote Denial of Service" visible="true"/><rule ruleid="30305" enabled="true" group="136315066" action=" db  screen " name="通过Web服务访问JRun默认配置文件jrun.ini" name_chs="通过Web服务访问JRun默认配置文件jrun.ini" name_eng="Access to JRun Default Congif File jrun.ini" visible="true"/><rule ruleid="40619" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Sober.E@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Sober.E@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Sober.E@mm" visible="true"/><rule ruleid="40262" enabled="true" group="69214266" action=" db  screen " name="Mailers cgimail.exe CGI程序漏洞扫描探测" name_chs="Mailers cgimail.exe CGI程序漏洞扫描探测" name_eng="Mailers cgimail.exe CGI Vulnerability Detection" visible="true"/><rule ruleid="40265" enabled="true" group="69206206" action=" db  screen  drop " name="利用Microsoft NTFS ::$DATA漏洞获取ASP源码攻击" name_chs="利用Microsoft NTFS ::$DATA漏洞获取ASP源码攻击" name_eng="ASP Source Code Disclosure via Microsoft NTFS ::$DATA Vulnerability" visible="true"/><rule ruleid="40348" enabled="true" group="69206222" action=" db  screen " name="利用&quot;../字串突破CGI脚本过滤访问上级目录" name_chs="利用&quot;../字串突破CGI脚本过滤访问上级目录" name_eng="CGI Script Filter Bypass And Upper Directory Access via &quot;../ String" visible="true"/><rule ruleid="20612" enabled="true" group="69206187" action=" db  screen " name="TrackerCam PHP参数远程缓冲区溢出攻击" name_chs="TrackerCam PHP参数远程缓冲区溢出攻击" name_eng="TrackerCam PHP Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20613" enabled="true" group="156239911" action=" db  screen " name="SGI IRIX lpsched远程命令执行攻击" name_chs="SGI IRIX lpsched远程命令执行攻击" name_eng="SGI IRIX lpsched Remote Command Execution" visible="true"/><rule ruleid="20610" enabled="true" group="166725671" action=" db  screen " name="DistCC守护程序远程命令执行攻击" name_chs="DistCC守护程序远程命令执行攻击" name_eng="DistCC Daemon Remote Command Execution" visible="true"/><rule ruleid="20611" enabled="true" group="78643495" action=" db  screen " name="TFTPD服务超长文件名远程缓冲区溢出攻击" name_chs="TFTPD服务超长文件名远程缓冲区溢出攻击" name_eng="TFTPD Service Over-long Filename Remote Buffer Overflow" visible="true"/><rule ruleid="20616" enabled="true" group="203423915" action=" db  screen " name="Symantec Sygate Management Server认证Applet远程SQL注入攻击" name_chs="Symantec Sygate Management Server认证Applet远程SQL注入攻击" name_eng="Symantec Sygate Management Server Authentication Applet Remote SQL Injection" visible="true"/><rule ruleid="20617" enabled="true" group="99615019" action=" db  screen " name="Sentinel License Manager Lservnt服务远程缓冲区溢出攻击" name_chs="Sentinel License Manager Lservnt服务远程缓冲区溢出攻击" name_eng="Sentinel License Manager Lservnt Service Remote Buffer Overflow" visible="true"/><rule ruleid="20614" enabled="true" group="78643495" action=" db  screen " name="FutureSoft TFTP Server 2000远程缓冲区溢出攻击" name_chs="FutureSoft TFTP Server 2000远程缓冲区溢出攻击" name_eng="FutureSoft TFTP Server 2000 Remote Buffer Overflow" visible="true"/><rule ruleid="20615" enabled="true" group="136315051" action=" db  screen " name="PAJAX pajax_call_dispatcher.php远程执行命令攻击" name_chs="PAJAX pajax_call_dispatcher.php远程执行命令攻击" name_eng="PAJAX pajax_call_dispatcher.php Remote Code Execution" visible="true"/><rule ruleid="20618" enabled="true" group="203423918" action=" db  screen " name="MyBB usercp.php获取管理用户权限攻击" name_chs="MyBB usercp.php获取管理用户权限攻击" name_eng="MyBB usercp.php Admin Privilege Escalation" visible="true"/><rule ruleid="20619" enabled="true" group="368050471" action=" db  screen " name="Apple Mac OS X AppleFileServer预验证远程缓冲区溢出攻击" name_chs="Apple Mac OS X AppleFileServer预验证远程缓冲区溢出攻击" name_eng="Apple Mac OS X AppleFileServer Pre-authentication Remote Buffer Overflow" visible="true"/><rule ruleid="20141" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序ksh" name_chs="通过Web服务访问Unix Shell解释程序ksh" name_eng="Access to Unix Shell Interpreter ksh via Web Service" visible="true"/><rule ruleid="50010" enabled="true" group="99647582" action=" db  screen " name="Windows系统远程管理工具PcAnywhere管理员远程登录" name_chs="Windows系统远程管理工具PcAnywhere管理员远程登录" name_eng="Windows Remote Management Tool PcAnywhere Administrator Remote Login" visible="true" merge="[t7200,si,di]"/><rule ruleid="20146" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序zsh" name_chs="通过Web服务访问Unix Shell解释程序zsh" name_eng="Access to Unix Shell Interpreter zsh via Web Service" visible="true"/><rule ruleid="20147" enabled="true" group="69214266" action=" db  screen " name="Microsoft JET catalog_type.asp脚本漏洞扫描探测" name_chs="Microsoft JET catalog_type.asp脚本漏洞扫描探测" name_eng="Microsoft JET catalog_type.asp Script Vulnerability Detection" visible="true"/><rule ruleid="20144" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序csh" name_chs="通过Web服务访问Unix Shell解释程序csh" name_eng="Access to Unix Shell Interpreter csh via Web Service" visible="true"/><rule ruleid="20145" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序rsh" name_chs="通过Web服务访问Unix Shell解释程序rsh" name_eng="Access to Unix Shell Interpreter rsh via Web Service" visible="true"/><rule ruleid="20854" enabled="true" group="74449194" action=" db  screen " name="PuTTy.exe v0.53 缓冲区溢出攻击" name_chs="PuTTy.exe v0.53 缓冲区溢出攻击" name_eng="PuTTy.exe v0.53 Buffer Overflow" visible="true"/><rule ruleid="20855" enabled="true" group="68157738" action=" db  screen " name="RealNetworks RealPlayer .smil文件处理缓冲区溢出攻击" name_chs="RealNetworks RealPlayer .smil文件处理缓冲区溢出攻击" name_eng="RealNetworks RealPlayer .smil File Prcocessing Buffer Overflow" visible="true"/><rule ruleid="20856" enabled="true" group="99615018" action=" db  screen " name="Real Networks Helix Universal Server RTSP Describe字段远程缓冲区溢出攻击" name_chs="Real Networks Helix Universal Server RTSP Describe字段远程缓冲区溢出攻击" name_eng="Real Networks Helix Universal Server RTSP Describe Field Remote Buffer Overflow" visible="true"/><rule ruleid="20857" enabled="true" group="99615018" action=" db  screen " name="WinVNC 客户程序缓冲区溢出攻击" name_chs="WinVNC 客户程序缓冲区溢出攻击" name_eng="WinVNC Client Buffer Overflow" visible="true"/><rule ruleid="20850" enabled="true" group="99615018" action=" db  screen " name="Novell Netmail NMAP服务STOR命令远程溢出攻击" name_chs="Novell Netmail NMAP服务STOR命令远程溢出攻击" name_eng="Novell Netmail NMAP Service STOR Command Remote Buffer Overflow" visible="true"/><rule ruleid="20851" enabled="true" group="70254890" action=" db  screen " name="FTP服务器PASS命令超长参数缓冲区溢出攻击" name_chs="FTP服务器PASS命令超长参数缓冲区溢出攻击" name_eng="FTP Server PASS Command Over-Long Parameter Buffer Overflow" visible="true"/><rule ruleid="20852" enabled="true" group="70254890" action=" db  screen " name="FTP服务器UNLOCK命令超长参数缓冲区溢出攻击" name_chs="FTP服务器UNLOCK命令超长参数缓冲区溢出攻击" name_eng="FTP Server UNLOCK Command Over-Long Parameter Buffer Overflow" visible="true"/><rule ruleid="20853" enabled="true" group="68157738" action=" db  screen " name="Proxy-Pro Professional GateKeeper Web代理缓冲区溢出攻击" name_chs="Proxy-Pro Professional GateKeeper Web代理缓冲区溢出攻击" name_eng="Proxy-Pro Professional GateKeeper Web Proxy Buffer Overflow" visible="true"/><rule ruleid="20859" enabled="true" group="72352042" action=" db  screen " name="POP3服务器PASS命令超长参数缓冲区溢出攻击" name_chs="POP3服务器PASS命令超长参数缓冲区溢出攻击" name_eng="POP3 Server PASS Command Over-Long Parameter Buffer Overflow" visible="true"/><rule ruleid="20149" enabled="true" group="69206187" action=" db  screen " name="扫描利用PERL工具远程执行命令" name_chs="扫描利用PERL工具远程执行命令" name_eng="Remote Code Execution via PERL Scan" visible="true"/><rule ruleid="20928" enabled="true" group="68159530" action=" db  screen " name="Trillian aim:// URI处理器远程代码执行攻击" name_chs="Trillian aim:// URI处理器远程代码执行攻击" name_eng="Trillian aim:// URI Processor Remote Code Execution Vulnerability" visible="true"/><rule ruleid="20929" enabled="true" group="99616810" action=" db  screen " name="AOL Instant Messenger通知窗口远程脚本执行攻击" name_chs="AOL Instant Messenger通知窗口远程脚本执行攻击" name_eng="AOL Instant Messenger Notification Window Remote Script Execution Vulnerability" visible="true"/><rule ruleid="20924" enabled="true" group="68159530" action=" db  screen " name="HP Software Update RulesEngine.dll控件远程文件覆盖攻击" name_chs="HP Software Update RulesEngine.dll控件远程文件覆盖攻击" name_eng="HP Software Update RulesEngine.dll Control Remote File Overwritten Vulnerability" visible="true"/><rule ruleid="20925" enabled="true" group="166723882" action=" db  screen " name="Asterisk SIP T.38 SDP解析远程栈溢出攻击" name_chs="Asterisk SIP T.38 SDP解析远程栈溢出攻击" name_eng="Asterisk SIP T.38 SDP Parsing Remote Stack Overflow Vulnerability" visible="true"/><rule ruleid="20926" enabled="true" group="162531370" action=" db  screen " name="Samba MS-RPC远程Shell命令注入执行攻击" name_chs="Samba MS-RPC远程Shell命令注入执行攻击" name_eng="Samba MS-RPC Remote Shell Command Injection Execution Vulnerability" visible="true"/><rule ruleid="20927" enabled="true" group="162529578" action=" db  screen " name="Samba NDR MS-RPC请求远程堆溢出攻击" name_chs="Samba NDR MS-RPC请求远程堆溢出攻击" name_eng="Samba NDR MS-RPC Request Remote Heap Overflow Vulnerability" visible="true"/><rule ruleid="20920" enabled="true" group="83886378" action=" db  screen " name="IMAP服务器SEARCH命令超长参数远程缓冲区溢出攻击" name_chs="IMAP服务器SEARCH命令超长参数远程缓冲区溢出攻击" name_eng="IMAP Server SEARCH Command Overly-long Parameter Remote Buffer Overflow Vulnerability" visible="true"/><rule ruleid="20921" enabled="true" group="68157738" action=" db  screen " name="Microsoft Windows柯达图像查看器远程代码执行攻击(MS07-055)" name_chs="Microsoft Windows柯达图像查看器远程代码执行攻击(MS07-055)" name_eng="Microsoft Windows Kodak Image Viewer Remote Code Execution Vulnerability" visible="true"/><rule ruleid="20922" enabled="true" group="95420714" action=" db  screen " name="Samba Send_MailSlot函数远程栈溢出攻击" name_chs="Samba Send_MailSlot函数远程栈溢出攻击" name_eng="Samba Send_MailSlot Function Remote Stack Overflow Vulnerability" visible="true"/><rule ruleid="20923" enabled="true" group="68157738" action=" db  screen " name="CA ETrust Intrusion Detection Caller.dll控件远程代码执行攻击" name_chs="CA ETrust Intrusion Detection Caller.dll控件远程代码执行攻击" name_eng="CA ETrust Intrusion Detection Caller.dll Control Remote Code Execution Vulnerability" visible="true"/><rule ruleid="10039" enabled="true" group="99616795" action=" db  screen  drop " name="OOB带外紧急数据Winuke拒绝服务攻击" name_chs="OOB带外紧急数据Winuke拒绝服务攻击" name_eng="OOB Emergency Data Winuke Denial of Service" visible="true"/><rule ruleid="20108" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.sadmind远程缓冲区溢出攻击" name_chs="Solaris rpc.sadmind远程缓冲区溢出攻击" name_eng="Solaris rpc.sadmind Remote Buffer Overflow" visible="true"/><rule ruleid="20109" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.sadmind服务存在性TCP扫描探测" name_chs="Solaris rpc.sadmind服务存在性TCP扫描探测" name_eng="Solaris rpc.sadmind Service TCP Detection" visible="true"/><rule ruleid="10035" enabled="false" group="99616794" action=" db  screen " name="Stream ACK/FIN小数据包洪流拒绝服务攻击" name_chs="Stream ACK/FIN小数据包洪流拒绝服务攻击" name_eng="Malformed Stream ACK/FIN Small Packets Flood Denial of Service" visible="true"/><rule ruleid="20107" enabled="true" group="68157739" action=" db  screen " name="Microsoft FrontPage 2000 fp30reg.dll缓冲区溢出攻击" name_chs="Microsoft FrontPage 2000 fp30reg.dll缓冲区溢出攻击" name_eng="Microsoft FrontPage 2000 fp30reg.dll Buffer Overflow" visible="true"/><rule ruleid="20104" enabled="true" group="69207087" action=" db  screen  drop " name="Windows系统下Code Red网络蠕虫攻击" name_chs="Windows系统下Code Red网络蠕虫攻击" name_eng="Code Red Worm on Windows" visible="true" merge="[t86400,si]"/><rule ruleid="20105" enabled="true" group="69207087" action=" db  screen " name="Windows系统下Code Red II网络蠕虫攻击" name_chs="Windows系统下Code Red II网络蠕虫攻击" name_eng="Code Red II Worm on Windows" visible="true" merge="[t86400,si]"/><rule ruleid="20102" enabled="true" group="68157743" action=" db  screen  drop " name="Microsoft IIS .ida/.idq ISAPI扩展远程缓冲区溢出攻击" name_chs="Microsoft IIS .ida/.idq ISAPI扩展远程缓冲区溢出攻击" name_eng="Microsoft IIS .ida/.idq ISAPI Extension Remote Buffer Overflow" visible="true"/><rule ruleid="20100" enabled="true" group="68157739" action=" db  screen  drop " name="Microsoft IIS 4.0 .htr ISAPI扩展远程缓冲区溢出攻击" name_chs="Microsoft IIS 4.0 .htr ISAPI扩展远程缓冲区溢出攻击" name_eng="Microsoft IIS 4.0 .htr ISAPI Extension Remote Buffer Overflow" visible="true"/><rule ruleid="20101" enabled="true" group="83886383" action=" db  screen " name="Solaris ypbind UDP远程缓冲区溢出攻击" name_chs="Solaris ypbind UDP远程缓冲区溢出攻击" name_eng="Solaris ypbind UDP Remote Buffer Overflow" visible="true"/><rule ruleid="20781" enabled="true" group="69208106" action=" db  screen " name="McAfee ePolicy Orchestrator HTTP GET请求远程格式串攻击" name_chs="McAfee ePolicy Orchestrator HTTP GET请求远程格式串攻击" name_eng="McAfee ePolicy Orchestrator HTTP GET Request Remote Format String" visible="true"/><rule ruleid="20582" enabled="true" group="203423919" action=" db  screen " name="Claroline scormExport.inc.php远程文件包含攻击" name_chs="Claroline scormExport.inc.php远程文件包含攻击" name_eng="Claroline scormExport.inc.php Remote File Inclusion" visible="true"/><rule ruleid="20583" enabled="true" group="203423915" action=" db  screen " name="VWAR远程文件包含攻击" name_chs="VWAR远程文件包含攻击" name_eng="VWAR Remote File Inclusion" visible="true"/><rule ruleid="20580" enabled="true" group="166723883" action=" db  screen " name="PeerCast URL处理远程缓冲区溢出攻击" name_chs="PeerCast URL处理远程缓冲区溢出攻击" name_eng="PeerCast URL Handling Remote Buffer Overflow" visible="true"/><rule ruleid="20581" enabled="true" group="203423915" action=" db  screen " name="D2-Shoutbox load参数远程SQL注入攻击" name_chs="D2-Shoutbox load参数远程SQL注入攻击" name_eng="D2-Shoutbox load Parameter Remote SQL Injection" visible="true"/><rule ruleid="20586" enabled="true" group="136315051" action=" db  screen " name="phpWebSite hub_dir变量远程执行命令攻击" name_chs="phpWebSite hub_dir变量远程执行命令攻击" name_eng="phpWebSite hub_dir Variable Remote Command Execution" visible="true"/><rule ruleid="20587" enabled="true" group="203423915" action=" db  screen " name="Simplog tid参数远程SQL注入攻击" name_chs="Simplog tid参数远程SQL注入攻击" name_eng="Simplog tid Parameter Remote SQL Injection" visible="true"/><rule ruleid="20584" enabled="true" group="136315051" action=" db  screen " name="Horde Help模块远程执行命令攻击" name_chs="Horde Help模块远程执行命令攻击" name_eng="Horde Help Module Remote Command Execution" visible="true"/><rule ruleid="20585" enabled="true" group="136315051" action=" db  screen " name="Sysinfoscript sysinfo.cgi远程执行命令攻击" name_chs="Sysinfoscript sysinfo.cgi远程执行命令攻击" name_eng="Sysinfoscript sysinfo.cgi Remote Command Execution" visible="true"/><rule ruleid="20588" enabled="true" group="203423919" action=" db  screen " name="Invision Power Board search.php远程脚本代码注入攻击" name_chs="Invision Power Board search.php远程脚本代码注入攻击" name_eng="Invision Power Board search.php Remote Script Injection" visible="true"/><rule ruleid="20589" enabled="true" group="203423919" action=" db  screen " name="Advanced GuestBook for phpBB远程文件包含攻击" name_chs="Advanced GuestBook for phpBB远程文件包含攻击" name_eng="Advanced GuestBook for phpBB Remote File Inclusion" visible="true"/><rule ruleid="30149" enabled="true" group="69214270" action=" db  screen " name="Index Server .htw读取文件漏洞扫描探测" name_chs="Index Server .htw读取文件漏洞扫描探测" name_eng="Index Server .htw File Reading Vulnerability Detection" visible="true"/><rule ruleid="30148" enabled="true" group="136315051" action=" db  screen " name="利用Matt Tourtillott maillist.pl脚本漏洞远程执行命令" name_chs="利用Matt Tourtillott maillist.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via Matt Tourtillott maillist.pl Script Vulnerability" visible="true"/><rule ruleid="40059" enabled="true" group="233898069" action=" db  screen " name="ICMP路由请求消息" name_chs="ICMP路由请求消息" name_eng="ICMP Route Request Message" visible="true"/><rule ruleid="30143" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.cachefsd服务存在性TCP扫描探测" name_chs="Solaris rpc.cachefsd服务存在性TCP扫描探测" name_eng="Solaris rpc.cachefsd Service TCP Detection" visible="true"/><rule ruleid="30142" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.cachefsd服务存在性UDP扫描探测" name_chs="Solaris rpc.cachefsd服务存在性UDP扫描探测" name_eng="Solaris rpc.cachefsd Service UDP Detection" visible="true"/><rule ruleid="30493" enabled="true" group="136315066" action=" db  screen " name="利用ht://dig htsearch脚本漏洞读取系统文件" name_chs="利用ht://dig htsearch脚本漏洞读取系统文件" name_eng="System File Reading via ht://dig htsearch Script Vulneraility" visible="true"/><rule ruleid="20787" enabled="true" group="203423914" action=" db  screen " name="webSPELL gallery.php远程SQL注入攻击" name_chs="webSPELL gallery.php远程SQL注入攻击" name_eng="webSPELL gallery.php Remote SQL Injection" visible="true"/><rule ruleid="30495" enabled="true" group="69214261" action=" db  screen " name="Microsoft FrontPage 98 Extensions获取绝对路径信息攻击" name_chs="Microsoft FrontPage 98 Extensions获取绝对路径信息攻击" name_eng="Microsoft FrontPage 98 Extensions Absolute Path Information Disclosure" visible="true"/><rule ruleid="30494" enabled="true" group="69214261" action=" db  screen " name="扫描探测helpme.html/helpme2.html页面文件" name_chs="扫描探测helpme.html/helpme2.html页面文件" name_eng="helpme.html/helpme2.html Page File Detection" visible="true"/><rule ruleid="30145" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.cmsd服务存在性TCP扫描探测" name_chs="Solaris rpc.cmsd服务存在性TCP扫描探测" name_eng="Solaris rpc.cmsd Service TCP Detection" visible="true"/><rule ruleid="30496" enabled="true" group="69214265" action=" db  screen " name="利用SQLQHit.asp CGI脚本漏洞收集系统信息" name_chs="利用SQLQHit.asp CGI脚本漏洞收集系统信息" name_eng="System Information Collection via SQLQHit.asp CGI Script" visible="true"/><rule ruleid="40724" enabled="true" group="233898058" action=" db  screen " name="Windoiws系统下CYG恶意代码活动" name_chs="Windoiws系统下CYG恶意代码活动" name_eng="Windoiws CYG Malicious Code Activity" visible="true"/><rule ruleid="30549" enabled="true" group="203425850" action=" db  screen " name="LimeWire HTTP畸形请求访问系统文件攻击" name_chs="LimeWire HTTP畸形请求访问系统文件攻击" name_eng="LimeWire HTTP Malformed Request System File Access" visible="true"/><rule ruleid="30548" enabled="true" group="203423930" action=" db  screen " name="Vignette Application Portal远程敏感信息获取攻击" name_chs="Vignette Application Portal远程敏感信息获取攻击" name_eng="Vignette Application Portal Remote Sensitive Information Disclosure" visible="true"/><rule ruleid="30547" enabled="true" group="145754166" action=" db  screen " name="HP Ignite-UX TFTP访问口令文件攻击" name_chs="HP Ignite-UX TFTP访问口令文件攻击" name_eng="HP Ignite-UX TFTP Password File Access" visible="true"/><rule ruleid="30546" enabled="true" group="136315066" action=" db  screen " name="Linksys Web Camera Software next_file参数非授权访问系统文件攻击" name_chs="Linksys Web Camera Software next_file参数非授权访问系统文件攻击" name_eng="Linksys Web Camera Software next_file Parameter System File Unauthorized Access" visible="true"/><rule ruleid="30545" enabled="true" group="203423930" action=" db  screen " name="Logics Software LOG-FT远程读取系统文件攻击" name_chs="Logics Software LOG-FT远程读取系统文件攻击" name_eng="Logics Software LOG-FT Remote System File Read" visible="true"/><rule ruleid="30544" enabled="true" group="136315066" action=" db  screen " name="Javamail非授权访问系统文件攻击" name_chs="Javamail非授权访问系统文件攻击" name_eng="Javamail System File Unauthorized Access" visible="true"/><rule ruleid="30543" enabled="true" group="203423930" action=" db  screen " name="EMC Navisphere Manager目录遍历攻击" name_chs="EMC Navisphere Manager目录遍历攻击" name_eng="EMC Navisphere Manager Directory Traversal" visible="true"/><rule ruleid="40726" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Love66木马通信" name_chs="Windows系统下Love66木马通信" name_eng="Trojan Love66 Communication on Windows" visible="true"/><rule ruleid="30541" enabled="true" group="136315050" action=" db  screen " name="Barracuda Spam Firewall img.pl远程目录遍历攻击" name_chs="Barracuda Spam Firewall img.pl远程目录遍历攻击" name_eng="Barracuda Spam Firewall img.pl Remote Directory Traversal" visible="true"/><rule ruleid="30540" enabled="true" group="136315066" action=" db  screen " name="Subscribe Me Pro远程目录遍历攻击" name_chs="Subscribe Me Pro远程目录遍历攻击" name_eng="Subscribe Me Pro Remote Directory Traversal" visible="true"/><rule ruleid="40123" enabled="true" group="209780821" action=" db  screen " name="SMTP服务邮件转发失败" name_chs="SMTP服务邮件转发失败" name_eng="SMTP Service Mail Transmit Failure" visible="true" merge="[t7200,si,di]"/><rule ruleid="40120" enabled="true" group="209723450" action=" db  screen " name="SMTP服务EXPN命令获取root帐号信息" name_chs="SMTP服务EXPN命令获取root帐号信息" name_eng="SMTP Service EXPN Command root Account Information Disclosure" visible="true"/><rule ruleid="40727" enabled="true" group="99618891" action=" db  screen " name="Windows系统下ZXShell木马通信" name_chs="Windows系统下ZXShell木马通信" name_eng="Trojan ZXShell Communication on Windows" visible="true"/><rule ruleid="40127" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Priority木马通信" name_chs="Windows系统下Priority木马通信" name_eng="Trojan Priority Communication on Windows" visible="true"/><rule ruleid="40720" enabled="true" group="99618891" action=" db  screen " name="Windows系统下NetAngel木马通信" name_chs="Windows系统下NetAngel木马通信" name_eng="Trojan NetAngel Communication on Windows" visible="true"/><rule ruleid="30274" enabled="true" group="136315066" action=" db  screen " name="IRIX webdist.cgi脚本漏洞扫描探测" name_chs="IRIX webdist.cgi脚本漏洞扫描探测" name_eng="IRIX webdist.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40278" enabled="true" group="69214266" action=" db  screen " name="Microsoft IIS newdsn.exe脚本漏洞扫描探测" name_chs="Microsoft IIS newdsn.exe脚本漏洞扫描探测" name_eng="Microsoft IIS newdsn.exe Script Vulnerability Detection" visible="true"/><rule ruleid="40722" enabled="true" group="99618891" action=" db  screen " name="Windows系统下FallingStar木马通信" name_chs="Windows系统下FallingStar木马通信" name_eng="Trojan FallingStar Communication on Windows" visible="true"/><rule ruleid="40273" enabled="true" group="68159546" action=" db  screen " name="Microsoft IIS 4.0 异常编码请求" name_chs="Microsoft IIS 4.0 异常编码请求" name_eng="Microsoft IIS 4.0 Abnormal Encoding Request" visible="true"/><rule ruleid="40723" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Tabdim木马通信" name_chs="Windows系统下Tabdim木马通信" name_eng="Trojan Tabdim Communication on Windows" visible="true"/><rule ruleid="40274" enabled="true" group="69206223" action=" db  screen " name="通过Web服务执行getdrvs.exe程序" name_chs="通过Web服务执行getdrvs.exe程序" name_eng="getdrvs.exe Program Execution via Web Service" visible="true"/><rule ruleid="40687" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下DAGGER木马通信" name_chs="Windows系统下DAGGER木马通信" name_eng="Trojan DAGGER Communication on Windows" visible="true"/><rule ruleid="40686" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下BITS木马通信" name_chs="Windows系统下BITS木马通信" name_eng="Trojan BITS Communication on Windows" visible="true"/><rule ruleid="40685" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.BG蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.BG蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.BG" visible="true"/><rule ruleid="40684" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.BK@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.BK@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.BK@mm" visible="true"/><rule ruleid="40683" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.AX蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.AX蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.AX" visible="true"/><rule ruleid="40682" enabled="true" group="99615823" action=" db  screen " name="Windows系统下W32.Bropia蠕虫通过MSN传播" name_chs="Windows系统下W32.Bropia蠕虫通过MSN传播" name_eng="W32.Bropia Propagation via MSN on Windows" visible="true"/><rule ruleid="40698" enabled="true" group="99618887" action=" db  screen " name="Windows系统下冬日之恋木马通信" name_chs="Windows系统下冬日之恋木马通信" name_eng="Trojan WinterLove Communication on Windows" visible="true"/><rule ruleid="40699" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Spook 5.8木马通信" name_chs="Windows系统下Spook 5.8木马通信" name_eng="Trojan Spook 5.8 Communication on Windows" visible="true"/><rule ruleid="30376" enabled="true" group="203423927" action=" db  screen " name="利用Web Shopper shopper.cgi脚本漏洞远程浏览文件" name_chs="利用Web Shopper shopper.cgi脚本漏洞远程浏览文件" name_eng="Remote File Browsing via Web Shopper shopper.cgi Script Vulnerability" visible="true"/><rule ruleid="40690" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Executor木马通信" name_chs="Windows系统下Executor木马通信" name_eng="Trojan Executor Communication on Windows" visible="true"/><rule ruleid="40691" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Wow23木马通信" name_chs="Windows系统下Wow23木马通信" name_eng="Trojan Wow23 Communication on Windows" visible="true"/><rule ruleid="40692" enabled="true" group="233898058" action=" db  screen " name="ARP协议MAC地址请求回应淹没拒绝服务攻击" name_chs="ARP协议MAC地址请求回应淹没拒绝服务攻击" name_eng="ARP Protocol MAC Address Request Flood Denial of Service" visible="true"/><rule ruleid="40693" enabled="true" group="99618895" action=" db  screen " name="Windows系统下BackOrifice木马通信" name_chs="Windows系统下BackOrifice木马通信" name_eng="Trojan BackOrifice Communication on Windows" visible="true"/><rule ruleid="40694" enabled="true" group="99618887" action=" db  screen " name="Windows系统下寿鼠 1.1木马通信" name_chs="Windows系统下寿鼠 1.1木马通信" name_eng="Trojan Shoushu 1.1 Communication on Windows" visible="true"/><rule ruleid="40695" enabled="true" group="99618887" action=" db  screen " name="Windows系统下寿鼠 1.0木马通信" name_chs="Windows系统下寿鼠 1.0木马通信" name_eng="Trojan Shoushu 1.0 Communication on Windows" visible="true"/><rule ruleid="40696" enabled="true" group="99618887" action=" db  screen " name="Windows系统下网络公牛木马通信" name_chs="Windows系统下网络公牛木马通信" name_eng="Trojan Netbull Communication on Windows" visible="true"/><rule ruleid="40697" enabled="true" group="99618887" action=" db  screen " name="Windows系统下MagicLink木马通信" name_chs="Windows系统下MagicLink木马通信" name_eng="Trojan MagicLink Communication on Windows" visible="true"/><rule ruleid="40470" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Amanda木马通信" name_chs="Windows系统下Amanda木马通信" name_eng="Trojan Amanda Communication on Windows" visible="true"/><rule ruleid="40471" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下AOL ADMIN木马通信" name_chs="Windows系统下AOL ADMIN木马通信" name_eng="Trojan AOL ADMIN Communication on Windows" visible="true"/><rule ruleid="40472" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Asylum木马通信" name_chs="Windows系统下Asylum木马通信" name_eng="Trojan Asylum Communication on Windows" visible="true"/><rule ruleid="40473" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下B.F. Evolution木马通信" name_chs="Windows系统下B.F. Evolution木马通信" name_eng="Trojan B.F. Evolution Communication on Windows" visible="true"/><rule ruleid="40474" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Backage木马通信" name_chs="Windows系统下Backage木马通信" name_eng="Trojan Backage Communication on Windows" visible="true"/><rule ruleid="40475" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下BACKDOOR木马通信" name_chs="Windows系统下BACKDOOR木马通信" name_eng="Trojan BACKDOOR Communication on Windows" visible="true"/><rule ruleid="40476" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Balsitix木马通信" name_chs="Windows系统下Balsitix木马通信" name_eng="Trojan Balsitix Communication on Windows" visible="true"/><rule ruleid="40477" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Basic Hell木马通信" name_chs="Windows系统下Basic Hell木马通信" name_eng="Trojan Basic Hell Communication on Windows" visible="true"/><rule ruleid="40478" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下BDDT木马通信" name_chs="Windows系统下BDDT木马通信" name_eng="Trojan BDDT Communication on Windows" visible="true"/><rule ruleid="40479" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Bigorna木马通信" name_chs="Windows系统下Bigorna木马通信" name_eng="Trojan Bigorna Communication on Windows" visible="true"/><rule ruleid="30039" enabled="true" group="233840702" action=" db  screen " name="漏洞扫描器ISS Scanner PING操作" name_chs="漏洞扫描器ISS Scanner PING操作" name_eng="ISS Scanner PING Operation" visible="true"/><rule ruleid="30038" enabled="true" group="233840697" action=" db  screen " name="网络工具CyberKit PING操作" name_chs="网络工具CyberKit PING操作" name_eng="Network Tool CyberKit PING Operation" visible="true"/><rule ruleid="40676" enabled="true" group="203424847" action=" db  screen  drop " name="网络蠕虫Santy.C搜索目标主机" name_chs="网络蠕虫Santy.C搜索目标主机" name_eng="Worm Santy.C Searching Target Host" visible="true"/><rule ruleid="40677" enabled="true" group="203424847" action=" db  screen  drop " name="网络蠕虫Santy.A攻击目标主机" name_chs="网络蠕虫Santy.A攻击目标主机" name_eng="Worm Santy.A Attacking Target Host" visible="true"/><rule ruleid="40674" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Atak.G蠕虫病毒邮件" name_chs="SMTP服务发送W32.Atak.G蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Atak.G" visible="true"/><rule ruleid="40675" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Erkez.D蠕虫病毒邮件" name_chs="SMTP服务发送W32.Erkez.D蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Erkez.D" visible="true"/><rule ruleid="40672" enabled="true" group="75759691" action=" db  screen " name="SMTP服务发送VBS.Junkmail蠕虫病毒邮件" name_chs="SMTP服务发送VBS.Junkmail蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with VBS.Junkmail" visible="true"/><rule ruleid="40673" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Atak.F蠕虫病毒邮件" name_chs="SMTP服务发送W32.Atak.F蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Atak.F" visible="true"/><rule ruleid="40670" enabled="true" group="75759691" action=" db  screen " name="SMTP服务发送W32.Maslan.C蠕虫病毒邮件" name_chs="SMTP服务发送W32.Maslan.C蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Maslan.C" visible="true"/><rule ruleid="40671" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Acid Battery木马通信" name_chs="Windows系统下Acid Battery木马通信" name_eng="Trojan Acid Battery Communication on Windows" visible="true"/><rule ruleid="40678" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.AI蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.AI蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.AI" visible="true"/><rule ruleid="40679" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.AL蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.AL蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.AL" visible="true"/><rule ruleid="40461" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle@mm" visible="true"/><rule ruleid="40584" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Satans木马通信" name_chs="Windows系统下Satans木马通信" name_eng="Trojan Satans Communication on Windows" visible="true"/><rule ruleid="40585" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Scarab木马通信" name_chs="Windows系统下Scarab木马通信" name_eng="Trojan Scarab Communication on Windows" visible="true"/><rule ruleid="40586" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Schneckenkorn木马通信" name_chs="Windows系统下Schneckenkorn木马通信" name_eng="Trojan Schneckenkorn Communication on Windows" visible="true"/><rule ruleid="40587" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下SchoolBus木马通信" name_chs="Windows系统下SchoolBus木马通信" name_eng="Trojan SchoolBus Communication on Windows" visible="true"/><rule ruleid="40580" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Revenger木马通信" name_chs="Windows系统下Revenger木马通信" name_eng="Trojan Revenger Communication on Windows" visible="true"/><rule ruleid="40581" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下The Ripper木马通信" name_chs="Windows系统下The Ripper木马通信" name_eng="Trojan The Ripper Communication on Windows" visible="true"/><rule ruleid="40582" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Ruler木马通信" name_chs="Windows系统下Ruler木马通信" name_eng="Trojan Ruler Communication on Windows" visible="true"/><rule ruleid="40583" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下RUX木马通信" name_chs="Windows系统下RUX木马通信" name_eng="Trojan RUX Communication on Windows" visible="true"/><rule ruleid="40588" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下TCC木马通信" name_chs="Windows系统下TCC木马通信" name_eng="Trojan TCC Communication on Windows" visible="true"/><rule ruleid="40589" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下The Flu木马通信" name_chs="Windows系统下The Flu木马通信" name_eng="Trojan The Flu Communication on Windows" visible="true"/><rule ruleid="20150" enabled="true" group="88080687" action=" db  screen " name="Microsoft SQL Server 2000 Resolution服务远程堆缓冲区溢出攻击" name_chs="Microsoft SQL Server 2000 Resolution服务远程堆缓冲区溢出攻击" name_eng="Microsoft SQL Server 2000 Resolution Service Remote Heap Buffer Overflow" visible="true"/><rule ruleid="40665" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Inzae.B蠕虫病毒邮件" name_chs="SMTP服务发送W32.Inzae.B蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Inzae.B" visible="true"/><rule ruleid="50011" enabled="true" group="99647582" action=" db  screen " name="Windows系统远程管理工具PCAnywhere会话启动请求" name_chs="Windows系统远程管理工具PCAnywhere会话启动请求" name_eng="Windows Remote Management Tool PCAnywhere Session Launch Request" visible="true" merge="[t7200,si,di]"/><rule ruleid="40664" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Inzae.A蠕虫病毒邮件" name_chs="SMTP服务发送W32.Inzae.A蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Inzae.A" visible="true"/><rule ruleid="40667" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Salga.A蠕虫病毒邮件" name_chs="SMTP服务发送W32.Salga.A蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Salga.A" visible="true"/><rule ruleid="40666" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下流光广外女生木马建立连接" name_chs="Windows系统下流光广外女生木马建立连接" name_eng="Trojan Gwgirl Connection on Windows" visible="true"/><rule ruleid="40661" enabled="true" group="75759695" action=" db  screen " name="Windows系统下Mydoom.AH/AI/AJ/AK及W32.Bofra蠕虫传播" name_chs="Windows系统下Mydoom.AH/AI/AJ/AK及W32.Bofra蠕虫传播" name_eng="Windows Mydoom.AH/AI/AJ/AK and W32.Bofra Propagation" visible="true"/><rule ruleid="40660" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下流光Sensor木马建立连接" name_chs="Windows系统下流光Sensor木马建立连接" name_eng="Trojan Sensor Connection on Windows" visible="true"/><rule ruleid="20915" enabled="true" group="83886378" action=" db  screen " name="CA BrightStor ARCserve Backup多个远程缓冲区溢出及内存破坏攻击" name_chs="CA BrightStor ARCserve Backup多个远程缓冲区溢出及内存破坏攻击" name_eng="CA BrightStor ARCserve Backup Multiple Remote Buffer Overflow and Memory Corruption Vulnerabilities" visible="true"/><rule ruleid="30390" enabled="true" group="203423925" action=" db  screen " name="Ultimate PHP Board add.php脚本漏洞扫描利用" name_chs="Ultimate PHP Board add.php脚本漏洞扫描利用" name_eng="Ultimate PHP Board add.php Script Vulnerability Detection" visible="true"/><rule ruleid="20446" enabled="true" group="76546347" action=" db  screen " name="IMAP服务LIST命令畸形参数远程缓冲区溢出攻击" name_chs="IMAP服务LIST命令畸形参数远程缓冲区溢出攻击" name_eng="IMAP Service LIST Command Malformed Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="30391" enabled="true" group="203423930" action=" db  screen " name="Ultimate PHP Board viewtopic.php脚本漏洞扫描探测" name_chs="Ultimate PHP Board viewtopic.php脚本漏洞扫描探测" name_eng="Ultimate PHP Board viewtopic.php Script Vulnerability Detection" visible="true"/><rule ruleid="20445" enabled="true" group="75497775" action=" db  screen " name="MDaemon SMTP服务程序多个命令远程缓冲区攻击" name_chs="MDaemon SMTP服务程序多个命令远程缓冲区攻击" name_eng="MDaemon SMTP Server multiple Commands Remote Buffer Attack" visible="true"/><rule ruleid="20911" enabled="true" group="68157738" action=" db  screen " name="Microsoft Windows柯达图像查看器远程代码执行攻击(MS07-055)" name_chs="Microsoft Windows柯达图像查看器远程代码执行攻击(MS07-055)" name_eng="Microsoft Windows Kodak Image Viewer Remote Code Execution (MS07-055)" visible="true"/><rule ruleid="20913" enabled="true" group="99615018" action=" db  screen " name="Apple QuickTime RTSP响应头远程栈溢出攻击" name_chs="Apple QuickTime RTSP响应头远程栈溢出攻击" name_eng="Apple QuickTime RTSP Response Header Remote Stack Overflow" visible="true"/><rule ruleid="50163" enabled="true" group="99745881" action=" db  screen " name="P2P文件共享工具WinMX文件传输" name_chs="P2P文件共享工具WinMX文件传输" name_eng="P2P File Sharing Tool WinMX File Transmission" visible="true"/><rule ruleid="50162" enabled="true" group="99745881" action=" db  screen " name="P2P文件共享工具DC++通信" name_chs="P2P文件共享工具DC++通信" name_eng="P2P File Sharing Tool DC++ Communication" visible="true"/><rule ruleid="50161" enabled="true" group="99745881" action=" db  screen " name="P2P文件共享工具Kazaa用户登录" name_chs="P2P文件共享工具Kazaa用户登录" name_eng="P2P File Sharing Tool Kazaa User Login" visible="true"/><rule ruleid="50160" enabled="true" group="99745881" action=" db  screen " name="P2P文件共享工具Ares通信" name_chs="P2P文件共享工具Ares通信" name_eng="P2P File Sharing Tool Ares Communication" visible="true"/><rule ruleid="50167" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger解析服务器地址" name_chs="即时通信软件Yahoo Messenger解析服务器地址" name_eng="Instant Messaging Software Yahoo Messenger Server Address Parsing" visible="true"/><rule ruleid="50166" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Pager解析升级站点地址" name_chs="即时通信软件Yahoo Pager解析升级站点地址" name_eng="Instant Messaging Software Yahoo Pager Upgrade Website Address Parsing" visible="true"/><rule ruleid="50165" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger解析升级站点地址" name_chs="即时通信软件Yahoo Messenger解析升级站点地址" name_eng="Instant Messaging Software Yahoo Messenger Upgrade Website Address Parsing" visible="true"/><rule ruleid="50164" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger文件传输" name_chs="即时通信软件Yahoo Messenger文件传输" name_eng="Instant Messaging Software Yahoo Messenger File Transmission" visible="true"/><rule ruleid="50169" enabled="true" group="99745885" action=" db  screen " name="即时通信软件ICQ文件传输" name_chs="即时通信软件ICQ文件传输" name_eng="Instant Messaging Software ICQ File Transmission" visible="true"/><rule ruleid="50168" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN Messenger解析服务器地址" name_chs="即时通信软件MSN Messenger解析服务器地址" name_eng="Instant Messaging Software MSN Messenger Server Address Parsing" visible="true"/><rule ruleid="10108" enabled="true" group="83888159" action=" db  screen " name="Microsoft Windows 2000 RPC DCOM接口拒绝服务攻击" name_chs="Microsoft Windows 2000 RPC DCOM接口拒绝服务攻击" name_eng="Microsoft Windows 2000 RPC DCOM Interface Denial of Service" visible="true"/><rule ruleid="10105" enabled="false" group="300943390" action=" db  screen " name="Cisco IOS IPv4报文处理拒绝服务可疑攻击" name_chs="Cisco IOS IPv4报文处理拒绝服务可疑攻击" name_eng="Cisco IOS IPv4 Message Handling Suspicious Denial of Service" visible="true"/><rule ruleid="10106" enabled="true" group="300943390" action=" db  screen " name="Cisco IOS IPv4报文处理拒绝服务攻击" name_chs="Cisco IOS IPv4报文处理拒绝服务攻击" name_eng="Cisco IOS IPv4 Message Handling Denial of Service" visible="true" merge="[t3600,di]"/><rule ruleid="20629" enabled="true" group="203423915" action=" db  screen " name="Randshop header.inc.php远程执行命令攻击" name_chs="Randshop header.inc.php远程执行命令攻击" name_eng="Randshop header.inc.php Remote Code Execution" visible="true"/><rule ruleid="20628" enabled="true" group="69206315" action=" db  screen " name="IA WebMail Server超长GET请求远程缓冲区溢出攻击" name_chs="IA WebMail Server超长GET请求远程缓冲区溢出攻击" name_eng="IA WebMail Server Over-long GET Request Remote Buffer Overflow" visible="true"/><rule ruleid="20627" enabled="true" group="99615019" action=" db  screen " name="ShixxNOTE 6.net远程缓冲区溢出攻击" name_chs="ShixxNOTE 6.net远程缓冲区溢出攻击" name_eng="ShixxNOTE 6.net Remote Buffer Overflow" visible="true"/><rule ruleid="20626" enabled="true" group="337641771" action=" db  screen " name="SoftCart SoftCart.exe CGI远程缓冲区溢出攻击" name_chs="SoftCart SoftCart.exe CGI远程缓冲区溢出攻击" name_eng="SoftCart SoftCart.exe CGI Remote Buffer Overflow" visible="true"/><rule ruleid="20625" enabled="true" group="69206315" action=" db  screen " name="Novell eDirectory Server iMonitor远程缓冲区溢出攻击" name_chs="Novell eDirectory Server iMonitor远程缓冲区溢出攻击" name_eng="Novell eDirectory Server iMonitor Remote Buffer Overflow" visible="true"/><rule ruleid="20624" enabled="true" group="99615019" action=" db  screen " name="Novell ZENworks Desktop/Server管理远程缓冲区溢出攻击" name_chs="Novell ZENworks Desktop/Server管理远程缓冲区溢出攻击" name_eng="Novell ZENworks Desktop/Server Management Remote Buffer Overflow" visible="true"/><rule ruleid="20623" enabled="true" group="233832743" action=" db  screen " name="BomberClone错误消息处理远程缓冲区溢出攻击" name_chs="BomberClone错误消息处理远程缓冲区溢出攻击" name_eng="BomberClone Error Message Handling Remote Buffer Overflow" visible="true"/><rule ruleid="20622" enabled="true" group="233834539" action=" db  screen " name="BakBone NetVault远程内存破坏执行指令攻击" name_chs="BakBone NetVault远程内存破坏执行指令攻击" name_eng="BakBone NetVault Remote Memory Corruption Code Execution" visible="true"/><rule ruleid="20621" enabled="true" group="69206315" action=" db  screen " name="BadBlue ext.dll mfcisapicommand远程缓冲区溢出攻击" name_chs="BadBlue ext.dll mfcisapicommand远程缓冲区溢出攻击" name_eng="BadBlue ext.dll mfcisapicommand Remote Buffer Overflow" visible="true"/><rule ruleid="20620" enabled="false" group="69206311" action=" db  screen " name="Sybase EAServer WebConsol远程缓冲区溢出攻击" name_chs="Sybase EAServer WebConsol远程缓冲区溢出攻击" name_eng="Sybase EAServer WebConsol Remote Buffer Overflow" visible="false"/><rule ruleid="20821" enabled="true" group="68157738" action=" db  screen " name="Alt-N WebAdmin USER参数远程溢出攻击" name_chs="Alt-N WebAdmin USER参数远程溢出攻击" name_eng="Alt-N WebAdmin USER Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20820" enabled="true" group="68157738" action=" db  screen " name="Microsoft IIS 5.1远程缓冲区溢出攻击(MS07-041)" name_chs="Microsoft IIS 5.1远程缓冲区溢出攻击(MS07-041)" name_eng="Microsoft IIS 5.1 Remote Buffer Overflow (MS07-041)" visible="true"/><rule ruleid="20823" enabled="true" group="68157738" action=" db  screen " name="Apple Quicktime RTSP畸形URL处理缓冲区溢出攻击" name_chs="Apple Quicktime RTSP畸形URL处理缓冲区溢出攻击" name_eng="Apple Quicktime RTSP Malformed URL Processing Buffer Overflow" visible="true"/><rule ruleid="20822" enabled="true" group="68157738" action=" db  screen " name="Apple iTunes m3u/pls播放列表远程缓冲区溢出攻击" name_chs="Apple iTunes m3u/pls播放列表远程缓冲区溢出攻击" name_eng="Apple iTunes m3u/pls Playlist Remote Buffer Overflow" visible="true"/><rule ruleid="20824" enabled="true" group="70254890" action=" db  screen " name="FTP服务器MKD命令超长参数远程缓冲区溢出攻击" name_chs="FTP服务器MKD命令超长参数远程缓冲区溢出攻击" name_eng="FTP Server MKD Command Over-Long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20827" enabled="true" group="68157738" action=" db  screen " name="NCTsoft NCTAudioFile2 ActiveX控件远程栈溢出攻击" name_chs="NCTsoft NCTAudioFile2 ActiveX控件远程栈溢出攻击" name_eng="NCTsoft NCTAudioFile2 ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="20829" enabled="true" group="74449194" action=" db  screen " name="SSH Server Key Exchange Algorithm String缓冲区溢出攻击" name_chs="SSH Server Key Exchange Algorithm String缓冲区溢出攻击" name_eng="SSH Server Key Exchange Algorithm String Buffer Overflow" visible="true"/><rule ruleid="20828" enabled="true" group="68159530" action=" db  screen " name="Firefox location.QueryInterface()代码执行攻击" name_chs="Firefox location.QueryInterface()代码执行攻击" name_eng="Firefox location.QueryInterface() Code Execution" visible="true"/><rule ruleid="20489" enabled="true" group="203423915" action=" db  screen " name="PHP-Nuke marks.php CGI脚本远程SQL注入攻击" name_chs="PHP-Nuke marks.php CGI脚本远程SQL注入攻击" name_eng="PHP-Nuke marks.php CGI Script Remote SQL Injection" visible="true"/><rule ruleid="20488" enabled="true" group="222300207" action=" db  screen  drop " name="MySQL CREATE FUNCTION功能mysql.func表插入恶意函数库攻击" name_chs="MySQL CREATE FUNCTION功能mysql.func表插入恶意函数库攻击" name_eng="MySQL CREATE FUNCTION mysql.func Table Malicious Library Injection" visible="true"/><rule ruleid="20483" enabled="true" group="136315055" action=" db  screen " name="paFileDB CGI脚本远程SQL注入攻击" name_chs="paFileDB CGI脚本远程SQL注入攻击" name_eng="paFileDB CGI Script Remote SQL Injection" visible="true"/><rule ruleid="20482" enabled="true" group="99615019" action=" db  screen  drop " name="CA License Client/Server GBR请求缓冲区溢出攻击" name_chs="CA License Client/Server GBR请求缓冲区溢出攻击" name_eng="CA License Client/Server GBR Request Buffer Overflow" visible="true"/><rule ruleid="20481" enabled="true" group="203423919" action=" db  screen " name="利用VBulletin misc.php CGI脚本漏洞远程执行命令" name_chs="利用VBulletin misc.php CGI脚本漏洞远程执行命令" name_eng="Remote Code Execution via VBulletin misc.php CGI Script Vulnerability" visible="true"/><rule ruleid="20480" enabled="true" group="203423919" action=" db  screen " name="利用VBulletin forumdisplay.php CGI脚本漏洞远程执行命令" name_chs="利用VBulletin forumdisplay.php CGI脚本漏洞远程执行命令" name_eng="Remote Code Execution via VBulletin forumdisplay.php CGI Script Vulnerability" visible="true"/><rule ruleid="20487" enabled="true" group="222300207" action=" db  screen  drop " name="MySQL CREATE FUNCTION功能libc函数库插入执行代码攻击" name_chs="MySQL CREATE FUNCTION功能libc函数库插入执行代码攻击" name_eng="MySQL CREATE FUNCTION libc Insert Operation Code Execution" visible="true"/><rule ruleid="20486" enabled="true" group="76546347" action=" db  screen " name="Ipswitch IMAP超长EXAMINE命令参数缓冲区溢出攻击" name_chs="Ipswitch IMAP超长EXAMINE命令参数缓冲区溢出攻击" name_eng="Ipswitch IMAP Over-long EXAMINE Command Parameter Buffer Overflow" visible="true"/><rule ruleid="20485" enabled="true" group="136315055" action=" db  screen " name="UBB.threads editpost.php CGI脚本远程SQL注入攻击" name_chs="UBB.threads editpost.php CGI脚本远程SQL注入攻击" name_eng="UBB.threads editpost.php CGI Script Remote SQL Injection" visible="true"/><rule ruleid="20484" enabled="true" group="136315055" action=" db  screen " name="利用WEBInsta Limbo CGI脚本远程执行命令攻击" name_chs="利用WEBInsta Limbo CGI脚本远程执行命令攻击" name_eng="Remote Code Execution via WEBInsta Limbo CGI Script" visible="true"/><rule ruleid="20139" enabled="true" group="136315051" action=" db  screen " name="利用CdomainFree whois_raw.cgi脚本漏洞远程执行命令" name_chs="利用CdomainFree whois_raw.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via CdomainFree whois_raw.cgi Script Vulnerability" visible="true"/><rule ruleid="20138" enabled="true" group="136323110" action=" db  screen " name="WebSPIRS webspirs.cgi脚本漏洞扫描探测" name_chs="WebSPIRS webspirs.cgi脚本漏洞扫描探测" name_eng="WebSPIRS webspirs.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40388" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo主控端连接建立" name_chs="DDOS工具Trinoo主控端连接建立" name_eng="DDOS Tool Trinoo Console Connection" visible="true"/><rule ruleid="20132" enabled="true" group="69206191" action=" db  screen  drop " name="Microsoft IIS 4.0/5.0 Unicode解码漏洞攻击" name_chs="Microsoft IIS 4.0/5.0 Unicode解码漏洞攻击" name_eng="Microsoft IIS 4.0/5.0 Unicode Decoding Vulnerability" visible="true"/><rule ruleid="20131" enabled="true" group="136315050" action=" db  screen  drop " name="利用NCSA test-cgi脚本获得目录内容列表" name_chs="利用NCSA test-cgi脚本获得目录内容列表" name_eng="Directory Content Listing via NCSA test-cgi Script" visible="true"/><rule ruleid="20137" enabled="true" group="136315051" action=" db  screen  drop " name="利用IRIX pfdispaly.cgi脚本漏洞远程执行命令或读取文件" name_chs="利用IRIX pfdispaly.cgi脚本漏洞远程执行命令或读取文件" name_eng="Remote Code Execution or File Reading via IRIX pfdispaly.cgi Script Vulnerability" visible="true"/><rule ruleid="40069" enabled="true" group="137365547" action=" db  screen " name="FTP服务转换功能远程执行命令攻击" name_chs="FTP服务转换功能远程执行命令攻击" name_eng="FTP Service Switch Feature Remote Command Execution" visible="true"/><rule ruleid="30489" enabled="true" group="68159542" action=" db  screen " name="Windows Apache服务器请求路径处理遍历目录攻击" name_chs="Windows Apache服务器请求路径处理遍历目录攻击" name_eng="Windows Apache Server Request Path Handling Directory Traversal" visible="true"/><rule ruleid="30482" enabled="true" group="136315071" action=" db  screen " name="利用phpMyAdmin export.php脚本漏洞遍历目录攻击" name_chs="利用phpMyAdmin export.php脚本漏洞遍历目录攻击" name_eng="Directory Traversal via phpMyAdmin export.php Script Vulnerability" visible="true"/><rule ruleid="30483" enabled="true" group="99622974" action=" db  screen  drop " name="Microsoft Windows ASN.1库BER解码堆破坏漏洞扫描探测" name_chs="Microsoft Windows ASN.1库BER解码堆破坏漏洞扫描探测" name_eng="Microsoft Windows ASN.1 Base BER Decoding Heap Corruption Vulnerability Detection" visible="true"/><rule ruleid="30480" enabled="true" group="136315070" action=" db  screen " name="利用QuikStore Shopping Cart quikstore.cgi脚本漏洞远程读取任意文件" name_chs="利用QuikStore Shopping Cart quikstore.cgi脚本漏洞远程读取任意文件" name_eng="Remote Arbitrary File Reading via QuikStore Shopping Cart quikstore.cgi Script Vulnerability" visible="true"/><rule ruleid="30481" enabled="true" group="69214265" action=" db  screen " name="MDaemon form2raw.cgi脚本漏洞扫描探测" name_chs="MDaemon form2raw.cgi脚本漏洞扫描探测" name_eng="MDaemon form2raw.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30487" enabled="true" group="69206202" action=" db  screen " name="利用Microsoft IIS ISM.DLL文件名截断漏洞获取文件内容攻击" name_chs="利用Microsoft IIS ISM.DLL文件名截断漏洞获取文件内容攻击" name_eng="File Content Disclosure via Microsoft IIS ISM.DLL Filename Truncation Vulnerability" visible="true"/><rule ruleid="40065" enabled="true" group="99680346" action=" db  screen " name="Netopia Timbuktu Pro用户名/口令明文传输" name_chs="Netopia Timbuktu Pro用户名/口令明文传输" name_eng="Netopia Timbuktu Pro Username/Passowrd Transmission in Plain Text" visible="true"/><rule ruleid="20555" enabled="true" group="202375467" action=" db  screen " name="Oracle 9i XDB HTTP认证远程缓冲区溢出攻击" name_chs="Oracle 9i XDB HTTP认证远程缓冲区溢出攻击" name_eng="Oracle 9i XDB HTTP Authentication Remote Buffer Overflow" visible="true"/><rule ruleid="20554" enabled="true" group="203423915" action=" db  screen " name="WebCalendar activity_log.php CGI脚本SQL注入攻击" name_chs="WebCalendar activity_log.php CGI脚本SQL注入攻击" name_eng="WebCalendar activity_log.php CGI Script SQL Injection" visible="true"/><rule ruleid="20557" enabled="true" group="203423915" action=" db  screen " name="WEBInsta Limbo SERVER变量远程执行命令攻击" name_chs="WEBInsta Limbo SERVER变量远程执行命令攻击" name_eng="WEBInsta Limbo SERVER Variable Remote Command Execution" visible="true"/><rule ruleid="20004" enabled="true" group="136315047" action=" db  screen " name="利用Abe Timmerman zml.cgi脚本漏洞遍历目录" name_chs="利用Abe Timmerman zml.cgi脚本漏洞遍历目录" name_eng="Directory Traversal via Abe Timmerman zml.cgi Script Vulnerability" visible="true"/><rule ruleid="20003" enabled="true" group="203423926" action=" db  screen " name="B2 b2edit.showposts.php脚本漏洞扫描探测" name_chs="B2 b2edit.showposts.php脚本漏洞扫描探测" name_eng="B2 b2edit.showposts.php Script Vulnerability Detection" visible="true"/><rule ruleid="20002" enabled="true" group="136315066" action=" db  screen " name="WebGlimpse aglimpse脚本漏洞扫描探测" name_chs="WebGlimpse aglimpse脚本漏洞扫描探测" name_eng="WebGlimpse aglimpse Script Vulnerability Detection" visible="true"/><rule ruleid="20001" enabled="true" group="136315054" action=" db  screen " name="Slashcode admin.pl脚本漏洞扫描探测" name_chs="Slashcode admin.pl脚本漏洞扫描探测" name_eng="Slashcode admin.pl Script Vulnerability Detection" visible="true"/><rule ruleid="20552" enabled="true" group="76546347" action=" db  screen " name="MailEnable IMAP超长邮箱名W3C日志记录溢出攻击" name_chs="MailEnable IMAP超长邮箱名W3C日志记录溢出攻击" name_eng="MailEnable IMAP Over-long Mailbox Name W3C Log Buffer Overflow" visible="true"/><rule ruleid="20558" enabled="true" group="203423919" action=" db  screen " name="phpBB signature_bbcode_uid变量远程任意命令执行攻击" name_chs="phpBB signature_bbcode_uid变量远程任意命令执行攻击" name_eng="phpBB signature_bbcode_uid Variable Remote Arbitrary Command Execution" visible="true"/><rule ruleid="20009" enabled="true" group="137363751" action=" db  screen " name="AIX FTP Server远程缓冲区溢出攻击" name_chs="AIX FTP Server远程缓冲区溢出攻击" name_eng="AIX FTP Server Remote Buffer Overflow" visible="true"/><rule ruleid="20008" enabled="true" group="143655211" action=" db  screen " name="IMAP用户认证远程缓冲区溢出攻击" name_chs="IMAP用户认证远程缓冲区溢出攻击" name_eng="IMAP User Authentication Remote Buffer Overflow" visible="true"/><rule ruleid="30558" enabled="true" group="136315066" action=" db  screen " name="aBitWhizzy abitwhizzy.php远程目录遍历攻击" name_chs="aBitWhizzy abitwhizzy.php远程目录遍历攻击" name_eng="aBitWhizzy abitwhizzy.php Remote Directory Traversal" visible="true"/><rule ruleid="30550" enabled="true" group="136315066" action=" db  screen " name="Minis month参数远程目录遍历攻击" name_chs="Minis month参数远程目录遍历攻击" name_eng="Minis month Parameter Remote Directory Traversal" visible="true"/><rule ruleid="30551" enabled="true" group="203423930" action=" db  screen " name="Fastream NETFile FTP/Web Server远程目录遍历攻击" name_chs="Fastream NETFile FTP/Web Server远程目录遍历攻击" name_eng="Fastream NETFile FTP/Web Server Remote Directory Traversal" visible="true"/><rule ruleid="30552" enabled="true" group="294651962" action=" db  screen " name="Nokia SGSN DX200远程SNMP信息攻击" name_chs="Nokia SGSN DX200远程SNMP信息攻击" name_eng="Nokia SGSN DX200 Remote SNMP Request Information Disclosure" visible="true"/><rule ruleid="30553" enabled="true" group="136315065" action=" db  screen " name="Nokia Electronic Documentation远程获取目录列表攻击" name_chs="Nokia Electronic Documentation远程获取目录列表攻击" name_eng="Nokia Electronic Documentation Remote Directory List Disclosure" visible="true"/><rule ruleid="30554" enabled="true" group="136316985" action=" db  screen " name="WEB-INF目录远程获取信息攻击" name_chs="WEB-INF目录远程获取信息攻击" name_eng="WEB-INF Directory Remote Information Disclosure" visible="true"/><rule ruleid="30555" enabled="true" group="136315066" action=" db  screen " name="MRTG CGI远程读取任意文件攻击" name_chs="MRTG CGI远程读取任意文件攻击" name_eng="MRTG CGI Arbitrary Remote File Reading" visible="true"/><rule ruleid="30556" enabled="true" group="294651962" action=" db  screen " name="Avaya Cajun固件未公开SNMP共同体字符串访问攻击" name_chs="Avaya Cajun固件未公开SNMP共同体字符串访问攻击" name_eng="Avaya Cajun Firmware Undocummented SNMP Community String Access" visible="true"/><rule ruleid="30557" enabled="true" group="294651962" action=" db  screen " name="Orinoco OEM Residential Gateway远程获取SNMP口令攻击" name_chs="Orinoco OEM Residential Gateway远程获取SNMP口令攻击" name_eng="Orinoco OEM Residential Gateway Remote SNMP Password Disclosure" visible="true"/><rule ruleid="40118" enabled="true" group="142614586" action=" db  screen  drop " name="SMTP服务decode帐号存在性探测" name_chs="SMTP服务decode帐号存在性探测" name_eng="SMTP Service decode Account Detection" visible="true"/><rule ruleid="40115" enabled="true" group="142639143" action=" db  screen " name="Sendmail 5.x RCPT命令远程执行命令攻击" name_chs="Sendmail 5.x RCPT命令远程执行命令攻击" name_eng="Sendmail 5.x RCPT Remote Command Execution" visible="true"/><rule ruleid="40114" enabled="true" group="142639143" action=" db  screen  drop " name="Sendmail 5.58 DEBUG远程执行命令攻击" name_chs="Sendmail 5.58 DEBUG远程执行命令攻击" name_eng="Sendmail 5.58 DEBUG Remote Command Execution" visible="true"/><rule ruleid="50076" enabled="true" group="99745885" action=" db  screen " name="即时通信软件QQ用户登录（TCP）" name_chs="即时通信软件QQ用户登录（TCP）" name_eng="Instant Messaging Software QQ User Login (TCP)" visible="true"/><rule ruleid="50220" enabled="true" group="233963613" action=" db  screen " name="QQ超级旋风文件下载" name_chs="QQ超级旋风文件下载" name_eng="QQ SuperWave File Downloading Vulnerability" visible="true"/><rule ruleid="50222" enabled="true" group="233963613" action=" db  screen " name="播播视频软件流媒体播放" name_chs="播播视频软件流媒体播放" name_eng="Bobo Video Software Stream Media Player" visible="true"/><rule ruleid="50223" enabled="true" group="68223069" action=" db  screen " name="股票行情分析操作软件华泰证券用户登录" name_chs="股票行情分析操作软件华泰证券用户登录" name_eng="Stock Market Analysing Operating System Huatai Securities User Login" visible="true"/><rule ruleid="20313" enabled="true" group="144703787" action=" db  screen " name="BIND iquery远程缓冲区溢出攻击" name_chs="BIND iquery远程缓冲区溢出攻击" name_eng="BIND iquery Remote Buffer Overflow" visible="true"/><rule ruleid="20311" enabled="true" group="203423919" action=" db  screen " name="利用Invision Board ipchat.php脚本漏洞远程执行命令" name_chs="利用Invision Board ipchat.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Invision Board ipchat.php Script Vulnerability" visible="true"/><rule ruleid="20310" enabled="true" group="142606639" action=" db  screen  drop " name="Sendmail 8.12 邮件头处理远程缓冲区溢出攻击" name_chs="Sendmail 8.12 邮件头处理远程缓冲区溢出攻击" name_eng="Sendmail 8.12 Mail Header Handling Remote Buffer Overflow" visible="true"/><rule ruleid="20317" enabled="true" group="136315047" action=" db  screen " name="利用phping脚本漏洞远程执行命令" name_chs="利用phping脚本漏洞远程执行命令" name_eng="Remote Code Execution via phping Script Vulnerability" visible="true"/><rule ruleid="20316" enabled="true" group="137363759" action=" db  screen " name="FTP服务器长路径名缓冲区溢出攻击" name_chs="FTP服务器长路径名缓冲区溢出攻击" name_eng="FTP Server Long Path Name Buffer Overflow" visible="true"/><rule ruleid="20318" enabled="true" group="203423915" action=" db  screen " name="利用Webchat defines.php脚本漏洞远程执行命令" name_chs="利用Webchat defines.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Webchat defines.php Script Vulnerability" visible="true"/><rule ruleid="30154" enabled="true" group="136323130" action=" db  screen " name="NCSA test-cgi脚本漏洞扫描探测" name_chs="NCSA test-cgi脚本漏洞扫描探测" name_eng="NCSA test-cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30213" enabled="true" group="83894326" action=" db  screen " name="Solaris rpc.rwalld服务存在性TCP扫描探测" name_chs="Solaris rpc.rwalld服务存在性TCP扫描探测" name_eng="Solaris rpc.rwalld Service TCP Detection" visible="true"/><rule ruleid="30156" enabled="true" group="136323126" action=" db  screen " name="Skunkware view-source脚本漏洞扫描探测" name_chs="Skunkware view-source脚本漏洞扫描探测" name_eng="Skunkware view-source Script Vulnerability Detection" visible="true"/><rule ruleid="30157" enabled="true" group="136315062" action=" db  screen " name="利用Skunkware view-source脚本漏洞远程执行命令" name_chs="利用Skunkware view-source脚本漏洞远程执行命令" name_eng="Remote Code Execution via Skunkware view-source Script Vulnerability" visible="true"/><rule ruleid="30150" enabled="true" group="69206202" action=" db  screen " name="利用Index Server .htw漏洞远程读取文件" name_chs="利用Index Server .htw漏洞远程读取文件" name_eng="Remote File Reading via Index Server .htw Vulnerability" visible="true"/><rule ruleid="30152" enabled="true" group="136323126" action=" db  screen " name="BNB survey.cgi脚本漏洞扫描探测" name_chs="BNB survey.cgi脚本漏洞扫描探测" name_eng="BNB survey.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40707" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Beast木马通信" name_chs="Windows系统下Beast木马通信" name_eng="Trojan Beast Communication on Windows" visible="true"/><rule ruleid="40800" enabled="true" group="68223050" action=" db  screen " name="WinZip FileView ActiveX控件远程栈溢出攻击" name_chs="WinZip FileView ActiveX控件远程栈溢出攻击" name_eng="WinZip FileView ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="40803" enabled="true" group="68223050" action=" db  screen " name="Microsoft MDAC RDS.Dataspace ActiveX控件远程代码执行攻击" name_chs="Microsoft MDAC RDS.Dataspace ActiveX控件远程代码执行攻击" name_eng="Microsoft MDAC RDS.Dataspace ActiveX Control Remote Code Execution" visible="true"/><rule ruleid="40802" enabled="true" group="68223050" action=" db  screen " name="IE ADODB.Connection对象Execute函数内存破坏攻击" name_chs="IE ADODB.Connection对象Execute函数内存破坏攻击" name_eng="IE ADODB.Connection Object Execution Memory Corruption" visible="true"/><rule ruleid="30158" enabled="true" group="136323126" action=" db  screen " name="AnyForm AnyForm2脚本漏洞扫描探测" name_chs="AnyForm AnyForm2脚本漏洞扫描探测" name_eng="AnyForm AnyForm2 Script Vulnerability Detection" visible="true"/><rule ruleid="30159" enabled="true" group="136323130" action=" db  screen " name="IRIX pfdispaly.cgi脚本漏洞扫描探测" name_chs="IRIX pfdispaly.cgi脚本漏洞扫描探测" name_eng="IRIX pfdispaly.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40807" enabled="true" group="83951690" action=" db  screen " name="DCERPC协议通信数据编码异常" name_chs="DCERPC协议通信数据编码异常" name_eng="DCERPC Protocol Communication Data Abnormal Encoding" visible="true"/><rule ruleid="40806" enabled="true" group="68223050" action=" db  screen " name="HP Mercury Quality Center ActiveX控件远程栈溢出攻击" name_chs="HP Mercury Quality Center ActiveX控件远程栈溢出攻击" name_eng="HP Mercury Quality Center ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="30210" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.nisd服务存在性TCP扫描探测" name_chs="Solaris rpc.nisd服务存在性TCP扫描探测" name_eng="Solaris rpc.nisd Service TCP Detection" visible="true"/><rule ruleid="40489" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Cafeini木马通信" name_chs="Windows系统下Cafeini木马通信" name_eng="Trojan Cafeini Communication on Windows" visible="true"/><rule ruleid="40488" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下ButtMan木马通信" name_chs="Windows系统下ButtMan木马通信" name_eng="Trojan ButtMan Communication on Windows" visible="true"/><rule ruleid="40485" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Breach Pro木马通信" name_chs="Windows系统下Breach Pro木马通信" name_eng="Trojan Breach Pro Communication on Windows" visible="true"/><rule ruleid="40484" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Breach木马通信" name_chs="Windows系统下Breach木马通信" name_eng="Trojan Breach Communication on Windows" visible="true"/><rule ruleid="40487" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Buschtrommel木马通信" name_chs="Windows系统下Buschtrommel木马通信" name_eng="Trojan Buschtrommel Communication on Windows" visible="true"/><rule ruleid="40486" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Bugs木马通信" name_chs="Windows系统下Bugs木马通信" name_eng="Trojan Bugs Communication on Windows" visible="true"/><rule ruleid="40481" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Black Angel木马通信" name_chs="Windows系统下Black Angel木马通信" name_eng="Trojan Black Angel Communication on Windows" visible="true"/><rule ruleid="40480" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Bla木马通信" name_chs="Windows系统下Bla木马通信" name_eng="Trojan Bla Communication on Windows" visible="true"/><rule ruleid="40483" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Blazer/Sockets de Troie木马通信" name_chs="Windows系统下Blazer/Sockets de Troie木马通信" name_eng="Trojan Blazer/Sockets de Troie Communication on Windows" visible="true"/><rule ruleid="40482" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Blade Runner木马通信" name_chs="Windows系统下Blade Runner木马通信" name_eng="Trojan Blade Runner Communication on Windows" visible="true"/><rule ruleid="40643" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AR/AV/AVV/AU@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AR/AV/AVV/AU@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AR/AV/AVV/AU@mm" visible="true"/><rule ruleid="40642" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Mexer.E蠕虫病毒邮件" name_chs="SMTP服务发送W32.Mexer.E蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Mexer.E" visible="true"/><rule ruleid="40641" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.AB蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.AB蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.AB" visible="true"/><rule ruleid="40640" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.Y蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.Y蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.Y" visible="true"/><rule ruleid="40647" enabled="true" group="99615823" action=" db  screen " name="Windows系统下Worm.MSN.funny蠕虫通过MSN传播" name_chs="Windows系统下Worm.MSN.funny蠕虫通过MSN传播" name_eng="Worm.MSN.funny Propagation via MSN on Windows" visible="true"/><rule ruleid="40700" enabled="true" group="99618887" action=" db  screen " name="Windows系统下流萤 2.3木马通信" name_chs="Windows系统下流萤 2.3木马通信" name_eng="FireFly 2.3 Communication on Windows" visible="true"/><rule ruleid="40645" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Fili蠕虫病毒邮件" name_chs="SMTP服务发送W32.Fili蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Fili" visible="true"/><rule ruleid="40644" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.AC蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.AC蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.AC" visible="true"/><rule ruleid="40649" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.AD@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.AD@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.AD@mm" visible="true"/><rule ruleid="40648" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.AF蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.AF蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.AF" visible="true"/><rule ruleid="40243" enabled="true" group="69206202" action=" db  screen " name="利用PowerPlay ppdscgi.exe脚本漏洞获取信息" name_chs="利用PowerPlay ppdscgi.exe脚本漏洞获取信息" name_eng="Information Disclosure via PowerPlay ppdscgi.exe Script Vulnerability" visible="true"/><rule ruleid="30240" enabled="true" group="209723450" action=" db  screen " name="漏洞扫描器Cybercop Scanner EHLO命令探测SMTP服务" name_chs="漏洞扫描器Cybercop Scanner EHLO命令探测SMTP服务" name_eng="Cybercop Scanner EHLO Command Detecting SMTP Service" visible="true"/><rule ruleid="20426" enabled="true" group="163578159" action=" db  screen " name="CVS多次Entry已被修改或未被修改标记插入操作堆溢出攻击" name_chs="CVS多次Entry已被修改或未被修改标记插入操作堆溢出攻击" name_eng="CVS Multiple Entry Modified or Unmodified Mark Insert Operation Heap Overflow" visible="true"/><rule ruleid="50000" enabled="true" group="145817685" action=" db  screen " name="TFTP服务客户端从服务器端获取文件" name_chs="TFTP服务客户端从服务器端获取文件" name_eng="Server Files Disclosure to TFTP Service Client" visible="true"/><rule ruleid="50001" enabled="true" group="145817685" action=" db  screen " name="TFTP服务客户端企图获取服务器上一级目录文件" name_chs="TFTP服务客户端企图获取服务器上一级目录文件" name_eng="TFTP Service Client Attempting to Obtain Files of Upper Level Server Directory" visible="true"/><rule ruleid="50002" enabled="true" group="145817685" action=" db  screen " name="TFTP服务客户端企图获取服务器根目录文件" name_chs="TFTP服务客户端企图获取服务器根目录文件" name_eng="TFTP Service Client Attempting to Obtain Files in the Server Root Directory" visible="true"/><rule ruleid="50003" enabled="true" group="361824350" action=" db  screen " name="SNMP服务访问使用默认private口令" name_chs="SNMP服务访问使用默认private口令" name_eng="SNMP Service Access with Default private Password" visible="true"/><rule ruleid="50004" enabled="true" group="204537949" action=" db  screen " name="FTP服务ftp匿名用户认证" name_chs="FTP服务ftp匿名用户认证" name_eng="FTP Service ftp Anonymous User Authentication" visible="true"/><rule ruleid="50006" enabled="true" group="138444893" action=" db  screen " name="TELNET服务客户端使用ld_library_path环境变量" name_chs="TELNET服务客户端使用ld_library_path环境变量" name_eng="TELNET Service Client Using ld_library_path Environment Variable" visible="true"/><rule ruleid="50007" enabled="true" group="138444894" action=" db  screen " name="TELNET服务客户端使用ld_preload环境变量" name_chs="TELNET服务客户端使用ld_preload环境变量" name_eng="TELNET Service Client Using ld_preload Environment" visible="true"/><rule ruleid="70083" enabled="true" group="233865293" action="" name="TCP端口3连接请求" name_chs="TCP端口3连接请求" name_eng="TCP Port 3 Connection Request " visible="false"/><rule ruleid="70081" enabled="true" group="73433165" action="" name="Windows系统NETBIOS 137端口扫描" name_chs="Windows系统NETBIOS 137端口扫描" name_eng="Scan on Port 137 for Windows NETBIOS " visible="false"/><rule ruleid="30516" enabled="true" group="99616826" action=" db  screen " name="Veritas Backup Exec For Windows/NetWare使用内置口令访问攻击" name_chs="Veritas Backup Exec For Windows/NetWare使用内置口令访问攻击" name_eng="Veritas Backup Exec For Windows/NetWare Access via Built-in Password" visible="true"/><rule ruleid="30517" enabled="true" group="136315070" action=" db  screen " name="phpMyAdmin grab_globals.lib.php CGI脚本远程文件包含攻击" name_chs="phpMyAdmin grab_globals.lib.php CGI脚本远程文件包含攻击" name_eng="phpMyAdmin grab_globals.lib.php CGI Script Remote File Inclusion" visible="true"/><rule ruleid="70084" enabled="true" group="233840717" action="" name="ICMP PING扫描单包" name_chs="ICMP PING扫描单包" name_eng="Single ICMP PING Packet " visible="false"/><rule ruleid="20637" enabled="true" group="203423915" action=" db  screen " name="SQuery gore.php远程执行命令攻击" name_chs="SQuery gore.php远程执行命令攻击" name_eng="SQuery gore.php Remote Code Execution" visible="true"/><rule ruleid="30512" enabled="true" group="68159546" action=" db  screen " name="Microsoft IIS 5.0 &quot;Translate: f&quot;头标记获取源码攻击" name_chs="Microsoft IIS 5.0 &quot;Translate: f&quot;头标记获取源码攻击" name_eng="Microsoft IIS 5.0 &quot;Translate: f&quot; Header Tag Source Code Execution" visible="true"/><rule ruleid="50178" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件大策略下载股票信息" name_chs="股票行情分析操作软件大策略下载股票信息" name_eng="Stock Market Analysis Software dcl Stock Information Downloading" visible="true"/><rule ruleid="50179" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件盘口王用户登录" name_chs="股票行情分析操作软件盘口王用户登录" name_eng="Stock Market Analysis Software Pankouwang User Login" visible="true"/><rule ruleid="50174" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件大智慧用户登录" name_chs="股票行情分析操作软件大智慧用户登录" name_eng="Stock Market Analysis Software Dazhihui User Login" visible="true"/><rule ruleid="50175" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件龙卷风用户登录" name_chs="股票行情分析操作软件龙卷风用户登录" name_eng="Stock Market Analysis Software Tornado User Login" visible="true"/><rule ruleid="50176" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件分析家用户登录" name_chs="股票行情分析操作软件分析家用户登录" name_eng="Stock Market Analysis Software Analyst User Login" visible="true"/><rule ruleid="50177" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件中国银河证券海王星用户登录" name_chs="股票行情分析操作软件中国银河证券海王星用户登录" name_eng="Stock Market Analysis Software China Galaxy Securities Neptune User Login" visible="true"/><rule ruleid="50170" enabled="true" group="99647582" action=" db  screen " name="Windows系统远程管理工具PcAnywhere登录连接" name_chs="Windows系统远程管理工具PcAnywhere登录连接" name_eng="Windows Remote Management Tool PcAnywhere Login Connection" visible="true"/><rule ruleid="50171" enabled="true" group="99680349" action=" db  screen " name="股票行情分析软件证券之星用户登录" name_chs="股票行情分析软件证券之星用户登录" name_eng="Stock Market Analysis Software stockstar.com Uesr Login" visible="true"/><rule ruleid="50172" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件同花顺用户登录" name_chs="股票行情分析操作软件同花顺用户登录" name_eng="Stock Market Analysis Software 10jqka.com.cn User Login" visible="true"/><rule ruleid="50173" enabled="true" group="99680349" action=" db  screen " name="股票行情分析操作软件钱龙旗舰用户登录" name_chs="股票行情分析操作软件钱龙旗舰用户登录" name_eng="Stock Market Analysis Software qianlong.com.cn User Login" visible="true"/><rule ruleid="40389" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo客户端向主控端发送默认口令" name_chs="DDOS工具Trinoo客户端向主控端发送默认口令" name_eng="DDOS Tool Tinoo Client Sending Default Password to the Console" visible="true"/><rule ruleid="30107" enabled="true" group="136315062" action=" db  screen  drop " name="利用Miva htmlscript脚本漏洞远程遍历目录读取文件" name_chs="利用Miva htmlscript脚本漏洞远程遍历目录读取文件" name_eng="Remote Directory Traversal File Reading via Miva htmlscript Script Vulnerability" visible="true"/><rule ruleid="30454" enabled="true" group="203423926" action=" db  screen " name="通过Web服务访问Cyber-Cats Chitchat口令文件" name_chs="通过Web服务访问Cyber-Cats Chitchat口令文件" name_eng="Access to Cyber-Cats Chitchat File via Web Service" visible="true"/><rule ruleid="30105" enabled="true" group="136315066" action=" db  screen " name="GuestBook guestbook.pl脚本漏洞扫描探测" name_chs="GuestBook guestbook.pl脚本漏洞扫描探测" name_eng="GuestBook guestbook.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30104" enabled="true" group="136315062" action=" db  screen " name="Feartech ftp.pl脚本漏洞扫描探测" name_chs="Feartech ftp.pl脚本漏洞扫描探测" name_eng="Feartech ftp.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30451" enabled="true" group="209715758" action=" db  screen " name="SMTP服务EXPN命令暴力猜测用户名攻击" name_chs="SMTP服务EXPN命令暴力猜测用户名攻击" name_eng="SMTP Service EXPN Command Username Brute Force" visible="true"/><rule ruleid="30101" enabled="true" group="136315066" action=" db  screen " name="Hylafax faxsurvey脚本漏洞扫描探测" name_chs="Hylafax faxsurvey脚本漏洞扫描探测" name_eng="Hylafax faxsurvey Script Vulnerability Detection" visible="true"/><rule ruleid="30452" enabled="true" group="209715758" action=" db  screen " name="SMTP服务VRFY命令暴力猜测用户名攻击" name_chs="SMTP服务VRFY命令暴力猜测用户名攻击" name_eng="SMTP Service VRFY Command Username Brute Force" visible="true"/><rule ruleid="20638" enabled="true" group="203423915" action=" db  screen " name="Phorum pm.php本地文件包含执行命令攻击" name_chs="Phorum pm.php本地文件包含执行命令攻击" name_eng="Phorum pm.php Local File Inclusion Remote Code Execution" visible="true"/><rule ruleid="20639" enabled="true" group="203423915" action=" db  screen " name="SimpleBoard sbp参数远程执行命令攻击" name_chs="SimpleBoard sbp参数远程执行命令攻击" name_eng="SimpleBoard sbp Parameter Remote Code Execution" visible="true"/><rule ruleid="20630" enabled="true" group="166723883" action=" db  screen " name="PoPToP PPTP read()参数负值远程缓冲区溢出攻击" name_chs="PoPToP PPTP read()参数负值远程缓冲区溢出攻击" name_eng="PoPToP PPTP read() Negative Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20631" enabled="true" group="166723883" action=" db  screen " name="Subversion日期解析函数缓冲区溢出攻击" name_chs="Subversion日期解析函数缓冲区溢出攻击" name_eng="Subversion Data Parsing function Buffer Overflow" visible="true"/><rule ruleid="20632" enabled="true" group="99615019" action=" db  screen " name="CA BrightStor ARCserve Backup发现服务远程缓冲区溢出攻击" name_chs="CA BrightStor ARCserve Backup发现服务远程缓冲区溢出攻击" name_eng="CA BrightStor ARCserve Backup Discovery Service Remote Buffer Overflow" visible="true"/><rule ruleid="20633" enabled="true" group="99615019" action=" db  screen " name="CA BrightStor ARCserve Backup UniversalAgent缓冲区溢出攻击" name_chs="CA BrightStor ARCserve Backup UniversalAgent缓冲区溢出攻击" name_eng="CA BrightStor ARCserve Backup UniversalAgent Buffer Overflow" visible="true"/><rule ruleid="20634" enabled="true" group="99615019" action=" db  screen " name="CA License Server GETCONFIG请求缓冲区溢出攻击" name_chs="CA License Server GETCONFIG请求缓冲区溢出攻击" name_eng="CA License Server GETCONFIG Request Buffer Overflow" visible="true"/><rule ruleid="20635" enabled="true" group="99615019" action=" db  screen " name="CA License Client GETCONFIG请求缓冲区溢出攻击" name_chs="CA License Client GETCONFIG请求缓冲区溢出攻击" name_eng="CA License Client GETCONFIG Request Buffer Overflow" visible="true"/><rule ruleid="20636" enabled="true" group="99615019" action=" db  screen " name="Veritas Backup Exec Remote Agent for Windows CONNECT_CLIENT_AUTH远程缓冲区溢出攻击" name_chs="Veritas Backup Exec Remote Agent for Windows CONNECT_CLIENT_AUTH远程缓冲区溢出攻击" name_eng="Veritas Backup Exec Remote Agent for Windows CONNECT_CLIENT_AUTH Remote Buffer Overflow" visible="true"/><rule ruleid="70085" enabled="true" group="361824349" action=" db  screen " name="SNMP服务使用默认public口令回应" name_chs="SNMP服务使用默认public口令回应" name_eng="SNMP Service Responding to Default public Password" visible="false"/><rule ruleid="20832" enabled="true" group="68157738" action=" db  screen " name="Microsoft Internet Explorer对象类型属性缓冲区溢出攻击（MS03-020)" name_chs="Microsoft Internet Explorer对象类型属性缓冲区溢出攻击（MS03-020)" name_eng="Microsoft Internet Explorer Object Type Attribute Buffer Overflow (MS03-020)" visible="true"/><rule ruleid="20833" enabled="true" group="68157738" action=" db  screen " name="HTTP协议认证字段超长溢出攻击" name_chs="HTTP协议认证字段超长溢出攻击" name_eng="HTTP Protocol Over-Long Authentication Field Buffer Overflow" visible="true"/><rule ruleid="20830" enabled="true" group="68157738" action=" db  screen " name="Ipswitch WhatsUp Gold远程缓冲区溢出攻击" name_chs="Ipswitch WhatsUp Gold远程缓冲区溢出攻击" name_eng="Ipswitch WhatsUp Gold Remote Buffer Overflow" visible="true"/><rule ruleid="20831" enabled="true" group="99615018" action=" db  screen " name="Kerio Personal Firewall验证包远程缓冲区溢出攻击" name_chs="Kerio Personal Firewall验证包远程缓冲区溢出攻击" name_eng="Kerio Personal Firewall Authentication Packet Remote Buffer Overflow" visible="true"/><rule ruleid="20836" enabled="true" group="76546346" action=" db  screen " name="IMAP服务器LOGIN命令超长参数缓冲区溢出攻击" name_chs="IMAP服务器LOGIN命令超长参数缓冲区溢出攻击" name_eng="IMAP Server LOGIN Command Over-Long Parameter Buffer Overflow" visible="true"/><rule ruleid="20834" enabled="true" group="68157738" action=" db  screen " name="SAP-DB/MaxDB WebDBM远程缓冲区溢出攻击" name_chs="SAP-DB/MaxDB WebDBM远程缓冲区溢出攻击" name_eng="SAP-DB/MaxDB WebDBM Remote Buffer Overflow" visible="true"/><rule ruleid="20838" enabled="true" group="99615018" action=" db  screen " name="GoodTech Telnet Server缓冲区溢出攻击" name_chs="GoodTech Telnet Server缓冲区溢出攻击" name_eng="GoodTech Telnet Server Buffer Overflow" visible="true"/><rule ruleid="20839" enabled="true" group="89129258" action=" db  screen " name="Hummingbird InetD组件远程缓冲区溢出攻击" name_chs="Hummingbird InetD组件远程缓冲区溢出攻击" name_eng="Hummingbird InetD Component Remote Buffer Overflow" visible="true"/><rule ruleid="20124" enabled="true" group="144703791" action=" db  screen " name="ISC Bind 8 TSIG远程缓冲区溢出攻击" name_chs="ISC Bind 8 TSIG远程缓冲区溢出攻击" name_eng="ISC Bind 8 TSIG Remote Buffer Overflow" visible="true"/><rule ruleid="20125" enabled="true" group="136323130" action=" db  screen " name="Matt Tourtillott maillist.pl脚本漏洞扫描探测" name_chs="Matt Tourtillott maillist.pl脚本漏洞扫描探测" name_eng="Matt Tourtillott maillist.pl Script Vulnerability Detection" visible="true"/><rule ruleid="20948" enabled="true" group="99615018" action=" db  screen " name="McAfee E-Business Server预认证远程代码执行攻击" name_chs="McAfee E-Business Server预认证远程代码执行攻击" name_eng="McAfee E-Business Server Pre-Authentication Remote Code Execution Vulnerability" visible="true"/><rule ruleid="20949" enabled="true" group="68157738" action=" db  screen " name="Aurigma Image Uploader ImageUploader4.ocx ActiveX控件栈溢出攻击" name_chs="Aurigma Image Uploader ImageUploader4.ocx ActiveX控件栈溢出攻击" name_eng="Aurigma Image Uploader ImageUploader4.ocx ActiveX Control Stack Overflow Vulnerability" visible="true"/><rule ruleid="20122" enabled="true" group="156238127" action=" db  screen " name="Linux系统LPRng远程格式化串溢出攻击" name_chs="Linux系统LPRng远程格式化串溢出攻击" name_eng="Linux LPRng Remote Format String Overflow" visible="true"/><rule ruleid="20942" enabled="true" group="68157738" action=" db  screen " name="BitDefender在线扫描器OScan.OCX ActiveX控件堆溢出攻击" name_chs="BitDefender在线扫描器OScan.OCX ActiveX控件堆溢出攻击" name_eng="BitDefender Online Scanner OScan.OCX ActiveX Control Heap Overflow Vulnerability " visible="true"/><rule ruleid="20943" enabled="true" group="68157738" action=" db  screen " name="Lycos文件上传组件FileUploader.dll ActiveX控件堆溢出攻击" name_chs="Lycos文件上传组件FileUploader.dll ActiveX控件堆溢出攻击" name_eng="Lycos File Uploading Component FileUploader.dll ActiveX Control Heap Overflow Vulnerability" visible="true"/><rule ruleid="20940" enabled="true" group="68157738" action=" db  screen " name="AOL YGPPicEdit.dll ActiveX控件远程溢出攻击" name_chs="AOL YGPPicEdit.dll ActiveX控件远程溢出攻击" name_eng="AOL YGPPicEdit.dll ActiveX Control Remote Overflow Vulnerability" visible="true"/><rule ruleid="20941" enabled="true" group="68157738" action=" db  screen " name="IBM Lotus Domino Web Access上传模块ActiveX控件栈溢出攻击" name_chs="IBM Lotus Domino Web Access上传模块ActiveX控件栈溢出攻击" name_eng="IBM Lotus Domino Web Access Uploading Module ActiveX Control Stack Overflow Vulnerability" visible="true"/><rule ruleid="20946" enabled="true" group="68157738" action=" db  screen " name="Toshiba Surveillix MeIpCamX.DLL ActiveX控件远程栈溢出攻击" name_chs="Toshiba Surveillix MeIpCamX.DLL ActiveX控件远程栈溢出攻击" name_eng="Toshiba Surveillix MeIpCamX.DLL ActiveX Control Remote Stack Overflow Vulnerability" visible="true"/><rule ruleid="20129" enabled="true" group="137363759" action=" db  screen  drop " name="Wu-ftpd SITE EXEC命令远程格式串漏洞攻击" name_chs="Wu-ftpd SITE EXEC命令远程格式串漏洞攻击" name_eng="Wu-ftpd SITE EXEC Command Remote Format String Vulnerability" visible="true"/><rule ruleid="20944" enabled="true" group="68157738" action=" db  screen " name="HP Virtual Rooms hpvirtualrooms14.dll控件缓冲区溢出攻击" name_chs="HP Virtual Rooms hpvirtualrooms14.dll控件缓冲区溢出攻击" name_eng="HP Virtual Rooms hpvirtualrooms14.dll Control Buffer Overflow Vulnerability" visible="true"/><rule ruleid="20945" enabled="true" group="68157738" action=" db  screen " name="Microsoft Visual FoxPro vfp6r.dll ActiveX控件任意代码执行攻击" name_chs="Microsoft Visual FoxPro vfp6r.dll ActiveX控件任意代码执行攻击" name_eng="Microsoft Visual FoxPro vfp6r.dll ActiveX Control Arbitrary Code Execution vulnerability" visible="true"/><rule ruleid="10013" enabled="true" group="68159518" action=" db  screen " name="Microsoft IIS WebDAV PROPFIND拒绝服务漏洞攻击" name_chs="Microsoft IIS WebDAV PROPFIND拒绝服务漏洞攻击" name_eng="Microsoft IIS WebDAV PROPFIND Denial of Service" visible="true"/><rule ruleid="10017" enabled="true" group="70256671" action=" db  screen  drop " name="Microsoft FTP服务器STAT命令glob()扩展拒绝服务攻击" name_chs="Microsoft FTP服务器STAT命令glob()扩展拒绝服务攻击" name_eng="Microsoft FTP Server STAT Command Globbing Denial of Service" visible="true"/><rule ruleid="10016" enabled="true" group="69206174" action=" db  screen " name="访问ExAir示例脚本advsearch.asp拒绝服务攻击" name_chs="访问ExAir示例脚本advsearch.asp拒绝服务攻击" name_eng="Visiting ExAir Sample Script advsearch.asp Denial of Service" visible="true"/><rule ruleid="10015" enabled="true" group="68157598" action=" db  screen " name="Microsoft IIS fpcount.exe程序漏洞扫描探测" name_chs="Microsoft IIS fpcount.exe程序漏洞扫描探测" name_eng="Microsoft IIS fpcount.exe Vulnerability Detection" visible="true"/><rule ruleid="10014" enabled="true" group="69206171" action=" db  screen " name="利用OmniHTTPd visadmin.exe程序漏洞拒绝服务攻击" name_chs="利用OmniHTTPd visadmin.exe程序漏洞拒绝服务攻击" name_eng="Denial of Service via OmniHTTPd visadmin.exe Vulnerability" visible="true"/><rule ruleid="40639" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.W蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.W蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.W" visible="true"/><rule ruleid="20546" enabled="true" group="203423919" action=" db  screen " name="XML-RPC for PHP远程代码注入攻击" name_chs="XML-RPC for PHP远程代码注入攻击" name_eng="XML-RPC for PHP Remote Code Injection" visible="true"/><rule ruleid="20547" enabled="true" group="203423915" action=" db  screen " name="CuteNews远程PHP代码注入攻击" name_chs="CuteNews远程PHP代码注入攻击" name_eng="CuteNews Remote PHP Code Injection" visible="true"/><rule ruleid="20544" enabled="true" group="69206186" action=" db  screen " name="Microsoft IIS .htw远程跨站脚本攻击" name_chs="Microsoft IIS .htw远程跨站脚本攻击" name_eng="Microsoft IIS .htw Remote Cross-site Scripting" visible="true"/><rule ruleid="20545" enabled="true" group="136315051" action=" db  screen " name="Mantis bug_sponsorship_list_view_inc.php远程文件包含攻击" name_chs="Mantis bug_sponsorship_list_view_inc.php远程文件包含攻击" name_eng="Mantis bug_sponsorship_list_view_inc.php Remote File Inclusion" visible="true"/><rule ruleid="20542" enabled="true" group="99615023" action=" db  screen " name="Microsoft IE HRAlign客户端缓冲区溢出攻击" name_chs="Microsoft IE HRAlign客户端缓冲区溢出攻击" name_eng="Microsoft IE HRAlign Client Buffer Overflow" visible="true"/><rule ruleid="20543" enabled="true" group="99616815" action=" db  screen " name="Microsoft IE Object客户端数据远程命令执行攻击" name_chs="Microsoft IE Object客户端数据远程命令执行攻击" name_eng="Microsoft IE Object Client Data Remote Code Execution" visible="true"/><rule ruleid="20540" enabled="true" group="99615023" action=" db  screen " name="Microsoft Windows即插即用UMPNPMGR.DLL wsprintfW远程溢出攻击" name_chs="Microsoft Windows即插即用UMPNPMGR.DLL wsprintfW远程溢出攻击" name_eng="Microsoft Windows Plug and Play UMPNPMGR.DLL wsprintfW Remote Buffer Overflow" visible="true"/><rule ruleid="20541" enabled="true" group="99615023" action=" db  screen " name="Microsoft IE Object Tag客户端缓冲区溢出攻击" name_chs="Microsoft IE Object Tag客户端缓冲区溢出攻击" name_eng="Microsoft IE Object Tag Client Buffer Overflow" visible="true"/><rule ruleid="20548" enabled="true" group="166723887" action=" db  screen " name="Snort Back Orifice预处理器远程栈溢出攻击" name_chs="Snort Back Orifice预处理器远程栈溢出攻击" name_eng="Snort Back Orifice Preprocessor Remote Stack Overflow" visible="true"/><rule ruleid="20549" enabled="true" group="203423919" action=" db  screen " name="Phorum search.php CGI脚本SQL注入攻击" name_chs="Phorum search.php CGI脚本SQL注入攻击" name_eng="Phorum search.php CGI Script SQL Injection" visible="true"/><rule ruleid="20553" enabled="true" group="99616815" action=" db  screen " name="Microsoft Windows MSDTC写任意内存地址攻击" name_chs="Microsoft Windows MSDTC写任意内存地址攻击" name_eng="Microsoft Windows MSDTC Arbitrary Memory Address Overwriting" visible="true"/><rule ruleid="10154" enabled="true" group="300943386" action=" db  screen " name="H.225协议sourceAddress url-ID数据畸形" name_chs="H.225协议sourceAddress url-ID数据畸形" name_eng="H.225 Protocol sourceAddress url-ID Malformed Data" visible="true"/><rule ruleid="20088" enabled="true" group="136315051" action=" db  screen  drop " name="利用WEBgais webgais脚本漏洞远程执行命令" name_chs="利用WEBgais webgais脚本漏洞远程执行命令" name_eng="Remote Code Execution via WEBgais webgais Script Vulnerability" visible="true"/><rule ruleid="20494" enabled="true" group="203423919" action=" db  screen " name="Invision Power Board index.php st参数远程SQL注入攻击" name_chs="Invision Power Board index.php st参数远程SQL注入攻击" name_eng="Invision Power Board index.php st Parameter Remote SQL Injection" visible="true"/><rule ruleid="20495" enabled="true" group="203423919" action=" db  screen " name="phpBB kb.php CGI脚本SQL注入攻击" name_chs="phpBB kb.php CGI脚本SQL注入攻击" name_eng="phpBB kb.php CGI Script SQL Injection" visible="true"/><rule ruleid="20496" enabled="true" group="203423919" action=" db  screen " name="UBB.threads printthread.php CGI脚本SQL注入攻击" name_chs="UBB.threads printthread.php CGI脚本SQL注入攻击" name_eng="UBB.threads printthread.php CGI Script SQL Injection" visible="true"/><rule ruleid="20497" enabled="true" group="75497775" action=" db  screen  drop " name="Microsoft Exchange Server SMTP服务畸形X-LINK2STATE命令远程溢出攻击" name_chs="Microsoft Exchange Server SMTP服务畸形X-LINK2STATE命令远程溢出攻击" name_eng="Microsoft Exchange Server SMTP Service Malformed X-LINK2STATE Command Remote Buffer Overflow" visible="true"/><rule ruleid="20490" enabled="true" group="203423915" action=" db  screen " name="利用phpCoin auxpage.php CGI脚本远程执行命令攻击" name_chs="利用phpCoin auxpage.php CGI脚本远程执行命令攻击" name_eng="Remote Code Execution via phpCoin auxpage.php CGI Script" visible="true"/><rule ruleid="20491" enabled="true" group="203423919" action=" db  screen " name="PunBB profile.php CGI脚本远程SQL注入攻击" name_chs="PunBB profile.php CGI脚本远程SQL注入攻击" name_eng="PunBB profile.php CGI Script Remote SQL Injection" visible="true"/><rule ruleid="20492" enabled="true" group="203423919" action=" db  screen " name="PostNuke News模块CGI脚本SQL注入攻击" name_chs="PostNuke News模块CGI脚本SQL注入攻击" name_eng="PostNuke News Module CGI Script Remote SQL Injection" visible="true"/><rule ruleid="20493" enabled="true" group="203423919" action=" db  screen " name="PHP-Nuke querylang参数CGI漏洞攻击" name_chs="PHP-Nuke querylang参数CGI漏洞攻击" name_eng="PHP-Nuke querylang Parameter CGI Vulnerability" visible="true"/><rule ruleid="20498" enabled="true" group="203423919" action=" db  screen " name="PhotoPost member.php CGI脚本SQL注入攻击" name_chs="PhotoPost member.php CGI脚本SQL注入攻击" name_eng="PhotoPost member.php CGI Script SQL Injection" visible="true"/><rule ruleid="20085" enabled="true" group="136315051" action=" db  screen  drop " name="利用Roar Smith info2www脚本漏洞远程执行命令" name_chs="利用Roar Smith info2www脚本漏洞远程执行命令" name_eng="Remote Code Execution via Roar Smith info2www Script Vulnerability" visible="true"/><rule ruleid="50153" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具Vagaa用户登录" name_chs="P2P文件共享工具Vagaa用户登录" name_eng="P2P File Sharing Tool Vagaa User Login" visible="true"/><rule ruleid="10159" enabled="true" group="136315034" action=" db  screen " name="Simple PHP Blog comment_delete_cgi.php远程文件删除攻击" name_chs="Simple PHP Blog comment_delete_cgi.php远程文件删除攻击" name_eng="Simple PHP Blog comment_delete_cgi.php Remote File Deletion" visible="true"/><rule ruleid="30239" enabled="true" group="209723450" action=" db  screen " name="漏洞扫描器Cybercop Scanner EXPN命令探测SMTP服务" name_chs="漏洞扫描器Cybercop Scanner EXPN命令探测SMTP服务" name_eng="Cybercop Scanner EXPN Command Detecting SMTP Service" visible="true"/><rule ruleid="30234" enabled="true" group="233840701" action=" db  screen " name="Traceroute ICMP/IPOPT探测网络拓扑操作" name_chs="Traceroute ICMP/IPOPT探测网络拓扑操作" name_eng="Traceroute ICMP/IPOPT Network Topology Detection" visible="true"/><rule ruleid="30237" enabled="true" group="202383418" action=" db  screen " name="漏洞扫描器Cybercop Scanner Web服务探测" name_chs="漏洞扫描器Cybercop Scanner Web服务探测" name_eng="Cybercop Scanner Web Service Detection" visible="true"/><rule ruleid="30236" enabled="true" group="233840701" action=" db  screen " name="Traceroute ICMP探测网络拓扑操作" name_chs="Traceroute ICMP探测网络拓扑操作" name_eng="Traceroute ICMP Network Topology Detection" visible="true"/><rule ruleid="20947" enabled="true" group="68157738" action=" db  screen " name="RTS Sentry PTZCamPanelCtrl ActiveX控件远程栈溢出攻击" name_chs="RTS Sentry PTZCamPanelCtrl ActiveX控件远程栈溢出攻击" name_eng="RTS Sentry PTZCamPanelCtrl ActiveX Control Remote Stack Overflow Vulnerability" visible="true"/><rule ruleid="20308" enabled="true" group="203423915" action=" db  screen " name="利用DotBr exec.php3脚本漏洞远程执行命令" name_chs="利用DotBr exec.php3脚本漏洞远程执行命令" name_eng="Remote Code Execution via DotBr exec.php3 Script Vulnerability" visible="true"/><rule ruleid="20309" enabled="true" group="203423915" action=" db  screen " name="利用DotBr system.php3脚本漏洞远程执行命令" name_chs="利用DotBr system.php3脚本漏洞远程执行命令" name_eng="Remote Code Execution via DotBr system.php3 Script Vulnerability" visible="true"/><rule ruleid="20304" enabled="true" group="203423915" action=" db  screen " name="利用emailreader_execute_on_each_page.inc.php脚本漏洞远程执行命令" name_chs="利用emailreader_execute_on_each_page.inc.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via emailreader_execute_on_each_page.inc.php Script Vulnerability" visible="true"/><rule ruleid="20305" enabled="true" group="203423915" action=" db  screen " name="利用email.php脚本漏洞远程执行命令" name_chs="利用email.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via email.php Script Vulnerability" visible="true"/><rule ruleid="20306" enabled="true" group="136315050" action=" db  screen " name="利用PHP-Nuke modules.php脚本漏洞获取口令HASH攻击" name_chs="利用PHP-Nuke modules.php脚本漏洞获取口令HASH攻击" name_eng="Password HASH Disclosure via PHP-Nuke modules.php Script Vulnerability" visible="true"/><rule ruleid="20307" enabled="true" group="136315051" action=" db  screen " name="利用D-Forum CGI脚本漏洞远程执行命令" name_chs="利用D-Forum CGI脚本漏洞远程执行命令" name_eng="Remote Code Execution via D-Forum CGI Script Vulnerability" visible="true"/><rule ruleid="20301" enabled="true" group="203423915" action=" db  screen " name="利用YABB SE news.php脚本漏洞远程执行命令" name_chs="利用YABB SE news.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via YABB SE news.php Script Vulnerability" visible="true"/><rule ruleid="20302" enabled="true" group="203423915" action=" db  screen " name="利用YABB SE packages.php脚本漏洞远程执行命令" name_chs="利用YABB SE packages.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via YABB SE packages.php Script Vulnerability" visible="true"/><rule ruleid="20303" enabled="true" group="136315047" action=" db  screen " name="利用myphpPageTool CGI脚本漏洞远程执行命令" name_chs="利用myphpPageTool CGI脚本漏洞远程执行命令" name_eng="Remote Code Execution via myphpPageTool CGI Script Vulnerability" visible="true"/><rule ruleid="30121" enabled="true" group="136315066" action=" db  screen " name="Matt Wright textcounter.pl脚本漏洞扫描探测" name_chs="Matt Wright textcounter.pl脚本漏洞扫描探测" name_eng="Matt Wright textcounter.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30120" enabled="true" group="69206202" action=" db  screen " name="利用Guestbook wguest.exe程序漏洞读取文件" name_chs="利用Guestbook wguest.exe程序漏洞读取文件" name_eng="File Reading via Guestbook wguest.exe Vulnerability" visible="true"/><rule ruleid="30123" enabled="true" group="136315066" action=" db  screen " name="WEBgais websendmail脚本漏洞扫描探测" name_chs="WEBgais websendmail脚本漏洞扫描探测" name_eng="WEBgais websendmail Script Vulnerability Detection" visible="true"/><rule ruleid="30122" enabled="true" group="136315066" action=" db  screen " name="WEBgais webgais脚本漏洞扫描探测" name_chs="WEBgais webgais脚本漏洞扫描探测" name_eng="WEBgais webgais Script Vulnerability Detection" visible="true"/><rule ruleid="30125" enabled="true" group="136315066" action=" db  screen " name="IRIX wrap脚本漏洞扫描探测" name_chs="IRIX wrap脚本漏洞扫描探测" name_eng="IRIX wrap Script Vulnerability Detection" visible="true"/><rule ruleid="30124" enabled="true" group="136315066" action=" db  screen " name="利用IRIX wrap脚本漏洞远程浏览服务器目录" name_chs="利用IRIX wrap脚本漏洞远程浏览服务器目录" name_eng="Remote Server Direcotry Browsing via IRIX wrap Script Vulnerability" visible="true"/><rule ruleid="30126" enabled="true" group="203423926" action=" db  screen " name="Zeroboard _head.php脚本漏洞扫描探测" name_chs="Zeroboard _head.php脚本漏洞扫描探测" name_eng="Zeroboard _head.php Script Vulnerability Detection" visible="true"/><rule ruleid="30128" enabled="false" group="69214270" action=" db  screen " name="Microsoft IIS 4.0 .htr ISAPI映射扫描探测" name_chs="Microsoft IIS 4.0 .htr ISAPI映射扫描探测" name_eng="Microsoft IIS 4.0 .htr ISAPI Mapping Detection" visible="true"/><rule ruleid="30059" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.rusersd服务存在性TCP扫描探测" name_chs="Solaris rpc.rusersd服务存在性TCP扫描探测" name_eng="Solaris rpc.rusersd Service TCP Detection" visible="true"/><rule ruleid="40498" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Dark Connection Inside木马通信" name_chs="Windows系统下Dark Connection Inside木马通信" name_eng="Trojan Dark Connection Inside Communication on Windows" visible="true"/><rule ruleid="40499" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下DFch木马通信" name_chs="Windows系统下DFch木马通信" name_eng="Trojan DFch Communication on Windows" visible="true"/><rule ruleid="40496" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下CrazzyNet木马通信" name_chs="Windows系统下CrazzyNet木马通信" name_eng="Trojan CrazzyNet Communication on Windows" visible="true"/><rule ruleid="40497" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Danton木马通信" name_chs="Windows系统下Danton木马通信" name_eng="Trojan Danton Communication on Windows" visible="true"/><rule ruleid="40494" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Connection木马通信" name_chs="Windows系统下Connection木马通信" name_eng="Trojan Connection Communication on Windows" visible="true"/><rule ruleid="40495" enabled="true" group="99618887" action=" db  screen  drop " name="Windows系统下Crack Down木马通信" name_chs="Windows系统下Crack Down木马通信" name_eng="Trojan Crack Down Communication on Windows" visible="true"/><rule ruleid="40492" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Bionet木马通信" name_chs="Windows系统下Bionet木马通信" name_eng="Trojan Bionet Communication on Windows" visible="true"/><rule ruleid="40493" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Chupacabra木马通信" name_chs="Windows系统下Chupacabra木马通信" name_eng="Trojan Chupacabra Communication on Windows" visible="true"/><rule ruleid="40490" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Celine木马通信" name_chs="Windows系统下Celine木马通信" name_eng="Trojan Celine Communication on Windows" visible="true"/><rule ruleid="40491" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Cero木马通信" name_chs="Windows系统下Cero木马通信" name_eng="Trojan Cero Communication on Windows" visible="true"/><rule ruleid="40658" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Spook木马建立连接" name_chs="Windows系统下Spook木马建立连接" name_eng="Trojan Spook Connection on Windows" visible="true"/><rule ruleid="40659" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下风雪木马客户端与服务端建立连接" name_chs="Windows系统下风雪木马客户端与服务端建立连接" name_eng="Trojan Snowdoor Client Connection to Server on Windows" visible="true"/><rule ruleid="40654" enabled="true" group="99618895" action=" db  screen " name="Windows系统下灰鸽子木马MINI版客户端连接服务器" name_chs="Windows系统下灰鸽子木马MINI版客户端连接服务器" name_eng="Trojan Huigezi MINI Client Connnection to Server on Windows" visible="true"/><rule ruleid="40655" enabled="true" group="99615819" action=" db  screen " name="Windows系统下Worm.Agobot蠕虫通过ISA防火墙活动" name_chs="Windows系统下Worm.Agobot蠕虫通过ISA防火墙活动" name_eng="Worm.Agobot on Windows Breaching ISA Firewall" visible="true"/><rule ruleid="40656" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下网络神偷木马通过80端口通信" name_chs="Windows系统下网络神偷木马通过80端口通信" name_eng="Nethief Communication on Port 80 on Windows" visible="true"/><rule ruleid="40657" enabled="true" group="72352075" action=" db  screen " name="POP3服务畸形邮件溢出客户端攻击" name_chs="POP3服务畸形邮件溢出客户端攻击" name_eng="POP3 Service Malformed Mail Overflow on Client" visible="true"/><rule ruleid="40650" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Darby蠕虫病毒邮件" name_chs="SMTP服务发送W32.Darby蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Darby" visible="true"/><rule ruleid="40651" enabled="true" group="203423950" action=" db  screen " name="利用CGI程序执行SQL注入攻击" name_chs="利用CGI程序执行SQL注入攻击" name_eng="SQL Injection Execution via CGI Program" visible="true"/><rule ruleid="40652" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下灰鸽子木马VIP专业版客户端连接服务器" name_chs="Windows系统下灰鸽子木马VIP专业版客户端连接服务器" name_eng="Trojan Huigezi VIP Professional Client and Server Connection" visible="true"/><rule ruleid="40653" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下灰鸽子木马辐射版客户端连接服务器" name_chs="Windows系统下灰鸽子木马辐射版客户端连接服务器" name_eng="Trojan Huigezi Radiation Client Connection to Server on Windows" visible="true"/><rule ruleid="40337" enabled="true" group="99618895" action=" db  screen " name="Windows系统下Netspy木马通信" name_chs="Windows系统下Netspy木马通信" name_eng="Trojan Netspy Trojan Communication on Windows" visible="true"/><rule ruleid="40336" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Subseven木马通信" name_chs="Windows系统下Subseven木马通信" name_eng="Trojan Subseven Communication on Windows" visible="true"/><rule ruleid="40335" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下wollf木马建立连接" name_chs="Windows系统下wollf木马建立连接" name_eng="Trojan wollf Connection on Windows" visible="true"/><rule ruleid="40250" enabled="true" group="69206223" action=" db  screen " name="通过Web服务执行.cmd程序" name_chs="通过Web服务执行.cmd程序" name_eng=".cmd Program Execution via Web Service" visible="true"/><rule ruleid="40334" enabled="true" group="99618895" action=" db  screen " name="Windows系统下xtcp木马建立连接" name_chs="Windows系统下xtcp木马建立连接" name_eng="Trojan xtcp Connection on Windows" visible="true"/><rule ruleid="40256" enabled="true" group="69214266" action=" db  screen " name="iCat Managers carbo.dll脚本漏洞扫描探测" name_chs="iCat Managers carbo.dll脚本漏洞扫描探测" name_eng="iCat Managers carbo.dll Script Vulnerability Detection" visible="true"/><rule ruleid="40258" enabled="true" group="69214271" action=" db  screen " name="Microsoft IIS 4.0 ism.dll脚本漏洞扫描探测" name_chs="Microsoft IIS 4.0 ism.dll脚本漏洞扫描探测" name_eng="Microsoft IIS 4.0 ism.dll Script Vulnerability Detection" visible="true"/><rule ruleid="40331" enabled="true" group="99618895" action=" db  screen " name="Windows系统下WinShell木马建立连接" name_chs="Windows系统下WinShell木马建立连接" name_eng="Trojan WinShell Connection on Windows" visible="true"/><rule ruleid="40330" enabled="true" group="99618895" action=" db  screen " name="Windows系统下tini木马连接建立" name_chs="Windows系统下tini木马连接建立" name_eng="Trojan tini Connection on Windows" visible="true"/><rule ruleid="50109" enabled="true" group="99745885" action=" db  screen " name="网络游戏石器时代客户端连接服务器" name_chs="网络游戏石器时代客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;Stone Age&quot;" visible="true"/><rule ruleid="50108" enabled="true" group="99745885" action=" db  screen " name="网络游戏坦克宝贝客户端连接服务器" name_chs="网络游戏坦克宝贝客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;Tankbaay&quot;" visible="true"/><rule ruleid="50101" enabled="true" group="99745885" action=" db  screen " name="网络游戏泡泡堂客户端连接服务器" name_chs="网络游戏泡泡堂客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;paopaotang&quot;" visible="true"/><rule ruleid="50100" enabled="true" group="99745885" action=" db  screen " name="网络游戏平台浩方对战登录" name_chs="网络游戏平台浩方对战登录" name_eng="Online Game Platform &quot;cga.com.cn&quot; Login" visible="true"/><rule ruleid="50103" enabled="true" group="99745885" action=" db  screen " name="网络游戏传奇世界客户端连接服务器" name_chs="网络游戏传奇世界客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;The Legend&quot;" visible="true"/><rule ruleid="50102" enabled="true" group="99745885" action=" db  screen " name="即时通信软件QQ访问游戏平台" name_chs="即时通信软件QQ访问游戏平台" name_eng="Instant Messaging Software QQ Game Access Platform" visible="true"/><rule ruleid="50105" enabled="true" group="99745885" action=" db  screen " name="网络游戏封神榜客户端连接服务器" name_chs="网络游戏封神榜客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;The Gods' Myth&quot;" visible="true"/><rule ruleid="50104" enabled="true" group="99745885" action=" db  screen " name="网络游戏大话西游客户端连接服务器" name_chs="网络游戏大话西游客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;Dahuaxiyou&quot;" visible="true"/><rule ruleid="50107" enabled="true" group="99745885" action=" db  screen " name="网络游戏平台联众游戏登录" name_chs="网络游戏平台联众游戏登录" name_eng="Online Game Platform &quot;Ourgame&quot; Login" visible="true"/><rule ruleid="50106" enabled="true" group="99745885" action=" db  screen " name="网络游戏剑侠情缘客户端连接服务器" name_chs="网络游戏剑侠情缘客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;Knights' Affection&quot;" visible="true"/><rule ruleid="50193" enabled="true" group="99745881" action=" db  screen " name="PPLive网络电视流媒体播放(UDP)" name_chs="PPLive网络电视流媒体播放(UDP)" name_eng="PPLive Network TV Streaming Media Playing (UDP)" visible="true"/><rule ruleid="30211" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.pcnfsd服务存在性TCP扫描探测" name_chs="Solaris rpc.pcnfsd服务存在性TCP扫描探测" name_eng="Solaris rpc.pcnfsd Service TCP Detection" visible="true"/><rule ruleid="20809" enabled="true" group="99615023" action=" db  screen " name="LanDesk管理套件Alert服务AOLSRVR.EXE缓冲区溢出攻击" name_chs="LanDesk管理套件Alert服务AOLSRVR.EXE缓冲区溢出攻击" name_eng="LanDesk Management Suite Alert Service AOLSRVR.EXE Buffer Overflow" visible="true"/><rule ruleid="20808" enabled="true" group="99615023" action=" db  screen " name="Microsoft Agent URI解析远程代码执行攻击" name_chs="Microsoft Agent URI解析远程代码执行攻击" name_eng="Microsoft Agent URI Resolution Remote Code Execution" visible="true"/><rule ruleid="20807" enabled="true" group="99615023" action=" db  screen  drop " name="Microsoft Windows UPnP远程栈溢出攻击" name_chs="Microsoft Windows UPnP远程栈溢出攻击" name_eng="Microsoft Windows UPnP Remote Stack Overflow" visible="true"/><rule ruleid="20804" enabled="true" group="83886383" action=" db  screen " name="Microsoft Windows DNS服务器RPC接口远程缓冲区溢出攻击" name_chs="Microsoft Windows DNS服务器RPC接口远程缓冲区溢出攻击" name_eng="Microsoft Windows DNS Server RPC Interface Remote Buffer Overflow" visible="true"/><rule ruleid="20803" enabled="true" group="88080554" action=" db  screen " name="PHPWind passport_client.php文件UPDATE参数远程SQL注入攻击" name_chs="PHPWind passport_client.php文件UPDATE参数远程SQL注入攻击" name_eng="PHPWind passport_client.php File UPDATE Parameter Remote SQL Injection" visible="true"/><rule ruleid="20802" enabled="true" group="76546346" action=" db  screen " name="IMAP服务器SUBSCRIBE命令超长参数远程缓冲区溢出攻击" name_chs="IMAP服务器SUBSCRIBE命令超长参数远程缓冲区溢出攻击" name_eng="IMAP Server SUBSCRIBE Command Over-Long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20801" enabled="true" group="83886378" action=" db  screen " name="CA Brightstor Backup Mediasvr.exe远程指令执行攻击" name_chs="CA Brightstor Backup Mediasvr.exe远程指令执行攻击" name_eng="CA Brightstor Backup Mediasvr.exe Remote Code Execution" visible="true"/><rule ruleid="20800" enabled="true" group="99615023" action=" db  screen " name="Microsoft Windows动画光标畸形ANI头结构远程栈溢出攻击" name_chs="Microsoft Windows动画光标畸形ANI头结构远程栈溢出攻击" name_eng="Microsoft Windows Cartoon Cursor Malformed ANI Header Structure Remote Stack Overflow" visible="true"/><rule ruleid="20151" enabled="true" group="88080687" action=" db  screen " name="Microsoft SQL Server 2000 Resolution服务远程栈缓冲区溢出攻击" name_chs="Microsoft SQL Server 2000 Resolution服务远程栈缓冲区溢出攻击" name_eng="Microsoft SQL Server 2000 Resolution Service Remote Stack Buffer Overflow" visible="true" merge="[t300,si]"/><rule ruleid="10005" enabled="true" group="150995231" action=" db  screen " name="Solaris rpc.ttdbserverd远程拒绝服务攻击" name_chs="Solaris rpc.ttdbserverd远程拒绝服务攻击" name_eng="Solaris rpc.ttdbserverd Remote Denial of Service" visible="true"/><rule ruleid="10006" enabled="true" group="165675307" action=" db  screen " name="Cassandra NNTPServer v1.10远程缓冲区溢出攻击" name_chs="Cassandra NNTPServer v1.10远程缓冲区溢出攻击" name_eng="Cassandra NNTPServer v1.10 Remote Buffer Overflow" visible="true"/><rule ruleid="10000" enabled="true" group="233834527" action=" db  screen  drop " name="IP重叠分片包Teardrop拒绝服务攻击" name_chs="IP重叠分片包Teardrop拒绝服务攻击" name_eng="IP Fragment Overlap Teardrop Denial of Service Attacks" visible="true"/><rule ruleid="10001" enabled="true" group="213911578" action=" db  screen " name="FINGER服务代理递归查询拒绝服务攻击" name_chs="FINGER服务代理递归查询拒绝服务攻击" name_eng="FINGER Service Agent Recursive Query Denial of Service" visible="true"/><rule ruleid="20157" enabled="true" group="142639143" action=" db  screen  drop " name="Sendmail 5.x MAIL命令远程执行命令攻击" name_chs="Sendmail 5.x MAIL命令远程执行命令攻击" name_eng="Sendmail 5.x MAIL Remote Command Execution" visible="true"/><rule ruleid="10009" enabled="true" group="69206174" action=" db  screen " name="访问Allaire ColdFusion startstop.html页面操作" name_chs="访问Allaire ColdFusion startstop.html页面操作" name_eng="Visiting Allaire ColdFusion startstop.html Page" visible="true"/><rule ruleid="20797" enabled="true" group="142606635" action=" db  screen " name="Exim auth_spa_server()缓冲区溢出攻击" name_chs="Exim auth_spa_server()缓冲区溢出攻击" name_eng="Exim auth_spa_server() Buffer Overflow" visible="true"/><rule ruleid="20796" enabled="true" group="233832747" action=" db  screen " name="Snort DCE/RPC预处理器远程缓冲区溢出攻击" name_chs="Snort DCE/RPC预处理器远程缓冲区溢出攻击" name_eng="Snort DCE/RPC Preprocessor Remote Buffer Overflow" visible="true"/><rule ruleid="20795" enabled="true" group="203423915" action=" db  screen " name="Wordpress 2.1.1远程命令执行后门攻击" name_chs="Wordpress 2.1.1远程命令执行后门攻击" name_eng="Wordpress 2.1.1 Remote Command Execution Backdoor" visible="true"/><rule ruleid="20794" enabled="true" group="203423914" action=" db  screen " name="PollMentor pollmentorres.asp远程SQL注入攻击" name_chs="PollMentor pollmentorres.asp远程SQL注入攻击" name_eng="PollMentor pollmentorres.asp Remote SQL Injection" visible="true"/><rule ruleid="20793" enabled="true" group="203423915" action=" db  screen " name="Nabopoll survey.inc.php远程文件包含攻击" name_chs="Nabopoll survey.inc.php远程文件包含攻击" name_eng="Nabopoll survey.inc.php Remote File Inclusion" visible="true"/><rule ruleid="20792" enabled="true" group="138414119" action=" db  screen " name="SunOS 5.10/5.11 TELNET服务远程绕过认证访问攻击" name_chs="SunOS 5.10/5.11 TELNET服务远程绕过认证访问攻击" name_eng="SunOS 5.10/5.11 TELNET Service Remote Authentication Bypass" visible="true"/><rule ruleid="20791" enabled="true" group="203423915" action=" db  screen " name="CM68 News oldnews.inc.php远程文件包含攻击" name_chs="CM68 News oldnews.inc.php远程文件包含攻击" name_eng="CM68 News oldnews.inc.php Remote File Inclusion" visible="true"/><rule ruleid="20790" enabled="true" group="203423915" action=" db  screen " name="Blog:CMS NP_UserSharing.php远程文件包含攻击" name_chs="Blog:CMS NP_UserSharing.php远程文件包含攻击" name_eng="Blog:CMS NP_UserSharing.php Remote File Inclusion" visible="true"/><rule ruleid="20391" enabled="true" group="99615023" action=" db  screen " name="Microsoft Windows ASN.1库BER解码堆破坏攻击" name_chs="Microsoft Windows ASN.1库BER解码堆破坏攻击" name_eng="Microsoft Windows ASN.1 Base BER Decoding Heap Corruption" visible="true"/><rule ruleid="20799" enabled="true" group="233834538" action=" db  screen " name="Helix Server DESCRIBE请求远程堆溢出攻击" name_chs="Helix Server DESCRIBE请求远程堆溢出攻击" name_eng="Helix Server DESCRIBE Request Remote Stack Overflow" visible="true"/><rule ruleid="20798" enabled="true" group="76546347" action=" db  screen " name="MailEnable APPEND命令畸形参数远程缓冲区溢出攻击" name_chs="MailEnable APPEND命令畸形参数远程缓冲区溢出攻击" name_eng="MailEnable APPEND Command Malformed Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20464" enabled="true" group="162529579" action=" db  screen  drop " name="Samba QFILEPATHINFO请求应答构造缓冲区溢出攻击" name_chs="Samba QFILEPATHINFO请求应答构造缓冲区溢出攻击" name_eng="Samba QFILEPATHINFO Request Response Structure Buffer Overflow" visible="true"/><rule ruleid="20395" enabled="true" group="82837807" action=" db  screen " name="Ipswitch IMail Server LDAP守护进程远程缓冲区溢出攻击" name_chs="Ipswitch IMail Server LDAP守护进程远程缓冲区溢出攻击" name_eng="Ipswitch IMail Server LDAP Daemon Remote Buffer Overflow" visible="true"/><rule ruleid="20573" enabled="true" group="136315055" action=" db  screen " name="AwStates Referer字段处理远程执行任意命令攻击" name_chs="AwStates Referer字段处理远程执行任意命令攻击" name_eng="AwStates Referer Field Handling Remote Arbitrary Command Execution" visible="true"/><rule ruleid="30377" enabled="true" group="203423927" action=" db  screen " name="Web Shopper shopper.cgi脚本漏洞扫描探测" name_chs="Web Shopper shopper.cgi脚本漏洞扫描探测" name_eng="Web Shopper shopper.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="20571" enabled="true" group="203423919" action=" db  screen " name="Invision Power Board Army Mod远程SQL注入攻击" name_chs="Invision Power Board Army Mod远程SQL注入攻击" name_eng="Invision Power Board Army Mod Remote SQL Injection" visible="true"/><rule ruleid="20570" enabled="true" group="136315051" action=" db  screen " name="RunCMS远程及本地文件包含攻击" name_chs="RunCMS远程及本地文件包含攻击" name_eng="RunCMS Remote and Local File Inclusion" visible="true"/><rule ruleid="20577" enabled="true" group="203423918" action=" db  screen " name="Mambo task参数远程SQL注入攻击" name_chs="Mambo task参数远程SQL注入攻击" name_eng="Mambo task Parameter Remote SQL Injection" visible="true"/><rule ruleid="20576" enabled="true" group="203423919" action=" db  screen " name="PHP-Nuke Your_Account模块远程SQL注入攻击" name_chs="PHP-Nuke Your_Account模块远程SQL注入攻击" name_eng="PHP-Nuke Your_Account Module Remote SQL Injection" visible="true"/><rule ruleid="20574" enabled="true" group="203423915" action=" db  screen " name="PLUME CMS prepend.php远程任意命令执行攻击" name_chs="PLUME CMS prepend.php远程任意命令执行攻击" name_eng="PLUME CMS prepend.php Remote Arbitrary Command Execution" visible="true"/><rule ruleid="30406" enabled="true" group="136316986" action=" db  screen " name="Apache Tomcat Snoop Servlet远程获取信息攻击" name_chs="Apache Tomcat Snoop Servlet远程获取信息攻击" name_eng="Apache Tomcat Snoop Servlet Remote Information Disclosure" visible="true"/><rule ruleid="20579" enabled="true" group="136315051" action=" db  screen " name="Guestbook Script本地文件包含执行命令攻击" name_chs="Guestbook Script本地文件包含执行命令攻击" name_eng="Guestbook Script Local File Inclusion Command Execution" visible="true"/><rule ruleid="20578" enabled="true" group="203423915" action=" db  screen " name="WEBInsta Limbo Itemid变量远程执行命令攻击" name_chs="WEBInsta Limbo Itemid变量远程执行命令攻击" name_eng="WEBInsta Limbo Itemid Variable Remote Command Execution" visible="true"/><rule ruleid="30408" enabled="true" group="203431993" action=" db  screen " name="Trend Micro Interscan Viruswall CGI程序缓冲区溢出漏洞扫描探测" name_chs="Trend Micro Interscan Viruswall CGI程序缓冲区溢出漏洞扫描探测" name_eng="Trend Micro Interscan Viruswall CGI Buffer Overflow Detection" visible="true"/><rule ruleid="40719" enabled="true" group="99618891" action=" db  screen " name="Windows系统下网络红娘木马通信" name_chs="Windows系统下网络红娘木马通信" name_eng="Trojan RedGirl Communication on Windows" visible="true"/><rule ruleid="40718" enabled="true" group="99618891" action=" db  screen " name="Windows系统下随意门木马通信" name_chs="Windows系统下随意门木马通信" name_eng="Trojan RandomDoor Communication on Windows" visible="true"/><rule ruleid="30228" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.ttdbserverd服务存在性TCP扫描探测" name_chs="Solaris rpc.ttdbserverd服务存在性TCP扫描探测" name_eng="Solaris rpc.ttdbserverd Service TCP Detection" visible="true"/><rule ruleid="40715" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Erazer Lite木马通信" name_chs="Windows系统下Erazer Lite木马通信" name_eng="Trojan Erazer Lite Communication on Windows" visible="true"/><rule ruleid="40714" enabled="true" group="99618891" action=" db  screen " name="Windows系统下CyberNetic木马通信" name_chs="Windows系统下CyberNetic木马通信" name_eng="Trojan CyberNetic Communication on Windows" visible="true"/><rule ruleid="40717" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Nuclear RAT木马通信" name_chs="Windows系统下Nuclear RAT木马通信" name_eng="Trojan Nuclear RAT Communication on Windows" visible="true"/><rule ruleid="40716" enabled="true" group="99618891" action=" db  screen " name="Windows系统下广外男生木马通信" name_chs="Windows系统下广外男生木马通信" name_eng="Trojan gwboy Communication on Windows" visible="true"/><rule ruleid="40711" enabled="true" group="99618887" action=" db  screen " name="Windows系统下黑洞木马通信" name_chs="Windows系统下黑洞木马通信" name_eng="Trojan Collapsar Communication on Windows" visible="true"/><rule ruleid="40710" enabled="true" group="99618891" action=" db  screen " name="Windows系统下CNNSC远程控制木马通信" name_chs="Windows系统下CNNSC远程控制木马通信" name_eng="Trojan CNNSC Remote Control Communication on Windows" visible="true"/><rule ruleid="40713" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Bandook木马通信" name_chs="Windows系统下Bandook木马通信" name_eng="Trojan Bandook Communication on Windows" visible="true"/><rule ruleid="40712" enabled="true" group="99618891" action=" db  screen " name="Windows系统下NCPH远程控制木马通信" name_chs="Windows系统下NCPH远程控制木马通信" name_eng="Trojan NCPH Remote Control Communication on Windows" visible="true"/><rule ruleid="40391" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo客户端向主控端发送默认口令" name_chs="DDOS工具Trinoo客户端向主控端发送默认口令" name_eng="DDOS Tool Trinoo Client Sending Default Password to the Console" visible="true"/><rule ruleid="40390" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo客户端向主控端发送默认口令" name_chs="DDOS工具Trinoo客户端向主控端发送默认口令" name_eng="DDOS Tool Trinoo Client Sending Default Password to the Console" visible="true"/><rule ruleid="40392" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo客户端向主控端发送默认口令" name_chs="DDOS工具Trinoo客户端向主控端发送默认口令" name_eng="DDOS Tool Trinoo Client Sending Default Password to the Console" visible="true"/><rule ruleid="40397" enabled="true" group="233898069" action=" db  screen " name="ICMP路由通告消息" name_chs="ICMP路由通告消息" name_eng="ICMP Route Notification Message" visible="true"/><rule ruleid="40109" enabled="false" group="166727755" action=" db  screen " name="DDOS工具Shaft SynFlood攻击" name_chs="DDOS工具Shaft SynFlood攻击" name_eng="DDOS Tool Shaft SynFlood" visible="true"/><rule ruleid="40399" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Doly Trojan 1.5木马建立连接" name_chs="Windows系统下Doly Trojan 1.5木马建立连接" name_eng="Doly Trojan 1.5 Connection on Windows" visible="true"/><rule ruleid="20370" enabled="true" group="150997039" action=" db  screen  drop " name="Solaris rpc.sadmind弱认证远程执行命令攻击" name_chs="Solaris rpc.sadmind弱认证远程执行命令攻击" name_eng="Solaris rpc.sadmind Weak Authentication Remote Command Execution" visible="true"/><rule ruleid="20372" enabled="true" group="83886383" action=" db  screen " name="Windows RPC DCOM接口长路径名远程堆缓冲区溢出攻击" name_chs="Windows RPC DCOM接口长路径名远程堆缓冲区溢出攻击" name_eng="Windows RPC DCOM Interface Long Path Name Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20374" enabled="true" group="99615807" action=" db  screen " name="Windows系统下RpcPatch_Mute蠕虫ICMP扫描活动" name_chs="Windows系统下RpcPatch_Mute蠕虫ICMP扫描活动" name_eng="Worm RpcPatch_Mute on Windows ICMP Scanning" visible="true" merge="[t300,si]"/><rule ruleid="20377" enabled="true" group="99615023" action=" db  screen  drop " name="Microsoft Windows Messenger服务远程堆溢出攻击" name_chs="Microsoft Windows Messenger服务远程堆溢出攻击" name_eng="Microsoft Windows Messenger Service Remote Heap Overflow" visible="true"/><rule ruleid="20376" enabled="true" group="138412335" action=" db  screen  drop " name="System V系统Login远程缓冲区溢出攻击" name_chs="System V系统Login远程缓冲区溢出攻击" name_eng="System V Login Remote Buffer Overflow" visible="true"/><rule ruleid="40000" enabled="false" group="99618891" action=" db  screen " name="Windows系统下Ackcmd木马程序通信" name_chs="Windows系统下Ackcmd木马程序通信" name_eng="Trojan Ackcmd Communication on Windows" visible="true"/><rule ruleid="40003" enabled="true" group="203423950" action=" db  screen " name="Web服务请求URL中使用%00恶意编码" name_chs="Web服务请求URL中使用%00恶意编码" name_eng="Malicious %00 Encoding in Web Service Request URL" visible="true"/><rule ruleid="30131" enabled="true" group="69214266" action=" db  screen " name="Microsoft FrontPage fp30reg.dll漏洞扫描探测" name_chs="Microsoft FrontPage fp30reg.dll漏洞扫描探测" name_eng="Microsoft FrontPage fp30reg.dll Vulnerability Detection" visible="true"/><rule ruleid="40004" enabled="true" group="99618894" action=" db  screen " name="Windows系统下MastersParadise木马建立连接" name_chs="Windows系统下MastersParadise木马建立连接" name_eng="Trojan MastersParadise Connection on Windows" visible="true"/><rule ruleid="30134" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.snmpXdmid服务存在性TCP扫描探测" name_chs="Solaris rpc.snmpXdmid服务存在性TCP扫描探测" name_eng="Solaris rpc.snmpXdmid Service TCP Detection" visible="true"/><rule ruleid="30135" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.snmpXdmid服务存在性UDP扫描探测" name_chs="Solaris rpc.snmpXdmid服务存在性UDP扫描探测" name_eng="Solaris rpc.snmpXdmid Service UDP Detection" visible="true"/><rule ruleid="30048" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.pcnfsd服务存在性UDP扫描探测" name_chs="Solaris rpc.pcnfsd服务存在性UDP扫描探测" name_eng="Solaris rpc.pcnfsd Service UDP Detection" visible="true"/><rule ruleid="30049" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.rexd服务存在性UDP扫描探测" name_chs="Solaris rpc.rexd服务存在性UDP扫描探测" name_eng="Solaris rpc.rexd Service UDP Detection" visible="true"/><rule ruleid="30042" enabled="true" group="151003190" action=" db  screen " name="SunOS rpc.selection_svc服务存在性UDP扫描探测" name_chs="SunOS rpc.selection_svc服务存在性UDP扫描探测" name_eng="SunOS rpc.selection_svc Service UDP Detection" visible="true"/><rule ruleid="30043" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.automountd服务存在性UDP扫描探测" name_chs="Solaris rpc.automountd服务存在性UDP扫描探测" name_eng="Solaris rpc.automountd Service UDP Detection" visible="true"/><rule ruleid="30040" enabled="true" group="233840702" action=" db  screen " name="端口扫描器Nmap PING操作" name_chs="端口扫描器Nmap PING操作" name_eng="Port Scanner Nmap PING Operation" visible="true" merge="[t86400,si]"/><rule ruleid="30041" enabled="true" group="151003199" action=" db  screen " name="SUNRPC服务信息DUMP查询" name_chs="SUNRPC服务信息DUMP查询" name_eng="SunRPC Service Information DUMP Query" visible="true"/><rule ruleid="30047" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.nisd服务存在性UDP扫描探测" name_chs="Solaris rpc.nisd服务存在性UDP扫描探测" name_eng="Solaris rpc.nisd Service UDP Detection" visible="true"/><rule ruleid="30044" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.bootparamd服务存在性UDP扫描探测" name_chs="Solaris rpc.bootparamd服务存在性UDP扫描探测" name_eng="Solaris rpc.bootparamd Service UDP Detection" visible="true"/><rule ruleid="40629" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Saros蠕虫病毒邮件" name_chs="SMTP服务发送W32.Saros蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Saros" visible="true"/><rule ruleid="40628" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Lovgate.AN/AO蠕虫变种病毒邮件" name_chs="SMTP服务发送W32.Lovgate.AN/AO蠕虫变种病毒邮件" name_eng="SMTP Service Sending Mails with W32.Lovgate.AN/AO Variant" visible="true"/><rule ruleid="40621" enabled="true" group="69210187" action=" db  screen " name="Yesadvertising Banking间谍软件活动" name_chs="Yesadvertising Banking间谍软件活动" name_eng="Yesadvertising Banking Spyware Activity" visible="true"/><rule ruleid="40620" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Sober.D@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Sober.D@mm蠕虫病毒邮件" name_eng="SMTP Servicec Sending Mails with W32.Sober.D@mm" visible="true"/><rule ruleid="40623" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AB/AX@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AB/AX@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AB/AX@mm" visible="true"/><rule ruleid="40625" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Lovgate蠕虫变种五毒虫病毒邮件" name_chs="SMTP服务发送W32.Lovgate蠕虫变种五毒虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Lovgate Variant Worm.Supnot" visible="true"/><rule ruleid="40624" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AG@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AG@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AG@mm" visible="true"/><rule ruleid="40627" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.P蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.P蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.P" visible="true"/><rule ruleid="40626" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.M蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.M蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.M" visible="true"/><rule ruleid="20205" enabled="true" group="203423911" action=" db  screen " name="利用calendar_admin.pl脚本漏洞远程执行命令" name_chs="利用calendar_admin.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via calendar_admin.pl Script Vulnerability" visible="true"/><rule ruleid="20207" enabled="true" group="88113199" action=" db  screen " name="Microsoft SQL Server xp_cmdshell存储过程执行命令攻击" name_chs="Microsoft SQL Server xp_cmdshell存储过程执行命令攻击" name_eng="Microsoft SQL Server xp_cmdshell Stored Procedure Command Execution" visible="true"/><rule ruleid="20206" enabled="true" group="203431990" action=" db  screen " name="calendar_admin.pl脚本漏洞扫描探测" name_chs="calendar_admin.pl脚本漏洞扫描探测" name_eng="calendar_admin.pl Script Vulnerability Detection" visible="true"/><rule ruleid="20201" enabled="true" group="138412331" action=" db  screen " name="IRIX telnetd远程格式化串溢出攻击" name_chs="IRIX telnetd远程格式化串溢出攻击" name_eng="IRIX telnetd Remote Format String Buffer Overflow" visible="true"/><rule ruleid="20200" enabled="true" group="69206202" action=" db  screen " name="Oracle Web Listener snork.bat批处理漏洞扫描利用" name_chs="Oracle Web Listener snork.bat批处理漏洞扫描利用" name_eng="Oracle Web Listener snork.bat Vulnerability Detection" visible="true"/><rule ruleid="20202" enabled="true" group="144705579" action=" db  screen " name="BIND NXT远程缓冲区溢出攻击" name_chs="BIND NXT远程缓冲区溢出攻击" name_eng="BIND NXT Remote Buffer Overflow" visible="true"/><rule ruleid="40104" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo主控端回应" name_chs="DDOS工具Trinoo主控端回应" name_eng="DDOS Tool Trinoo Console Response" visible="true"/><rule ruleid="20209" enabled="true" group="203423915" action=" db  screen " name="Phorum admin.php3脚本漏洞扫描利用" name_chs="Phorum admin.php3脚本漏洞扫描利用" name_eng="Phorum admin.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="20208" enabled="true" group="203423919" action=" db  screen " name="利用PHP-Nuke index.php脚本漏洞远程执行命令" name_chs="利用PHP-Nuke index.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via PHP-Nuke index.php Script Vulnerability" visible="true"/><rule ruleid="20499" enabled="true" group="203423915" action=" db  screen " name="利用GrayCMS error.php CGI脚本远程执行命令攻击" name_chs="利用GrayCMS error.php CGI脚本远程执行命令攻击" name_eng="GrayCMS error.php CGI Script Remote Command Execution" visible="true"/><rule ruleid="30242" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－普通扫描" name_chs="服务器端口扫描－普通扫描" name_eng="Server Port Scan - Normal Scan" visible="true"/><rule ruleid="40535" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下M2 Trojan木马通信" name_chs="Windows系统下M2 Trojan木马通信" name_eng="Trojan M2 Communication on Windows" visible="true"/><rule ruleid="40534" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Lithium木马通信" name_chs="Windows系统下Lithium木马通信" name_eng="Trojan Lithium Communication on Windows" visible="true"/><rule ruleid="40537" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Massaker木马通信" name_chs="Windows系统下Massaker木马通信" name_eng="Trojan Massaker Communication on Windows" visible="true"/><rule ruleid="40536" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mantis木马通信" name_chs="Windows系统下Mantis木马通信" name_eng="Trojan Mantis Communication on Windows" visible="true"/><rule ruleid="40531" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Latinus/Pest木马通信" name_chs="Windows系统下Latinus/Pest木马通信" name_eng="Trojan Latinus/Pest Communication on Windows" visible="true"/><rule ruleid="40530" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Last 2000木马通信" name_chs="Windows系统下Last 2000木马通信" name_eng="Trojan Last 2000 Communication on Windows" visible="true"/><rule ruleid="40533" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Leszcz木马通信" name_chs="Windows系统下Leszcz木马通信" name_eng="Trojan Leszcz Communication on Windows" visible="true"/><rule ruleid="40532" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Le Guardien木马通信" name_chs="Windows系统下Le Guardien木马通信" name_eng="Trojan Le Guardien Communication on Windows" visible="true"/><rule ruleid="40539" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Mavericks Matrix木马通信" name_chs="Windows系统下Mavericks Matrix木马通信" name_eng="Trojan Mavericks Matrix Communication on Windows" visible="true"/><rule ruleid="40538" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Masters Paradise木马通信" name_chs="Windows系统下Masters Paradise木马通信" name_eng="Trojan Masters Paradise Communication on Windows" visible="true"/><rule ruleid="30244" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－FIN扫描" name_chs="服务器端口扫描－FIN扫描" name_eng="Server Port Scan - FIN Scan" visible="true"/><rule ruleid="50124" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户发送可疑文件" name_chs="即时通信软件ICQ用户发送可疑文件" name_eng="Instant Messaging Software ICQ User Sending Suspicious Files" visible="true"/><rule ruleid="50118" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户下线" name_chs="即时通信软件ICQ用户下线" name_eng="Instant Messaging Software ICQ User Offline" visible="true"/><rule ruleid="50119" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户状态改变为离开" name_chs="即时通信软件ICQ用户状态改变为离开" name_eng="Instant Messaging Software ICQ User State Changed into &quot;Leave&quot;" visible="true"/><rule ruleid="50112" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger用户接收消息" name_chs="即时通信软件Yahoo Messenger用户接收消息" name_eng="Instant Messaging Software Yahoo Messenger User Receiving Messages" visible="true"/><rule ruleid="50113" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger用户下线" name_chs="即时通信软件Yahoo Messenger用户下线" name_eng="Instant Messaging Software Yahoo Messenger User Offline" visible="true"/><rule ruleid="50110" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger用户登录" name_chs="即时通信软件Yahoo Messenger用户登录" name_eng="Instant Messaging Software Yahoo Messenger User Login" visible="true"/><rule ruleid="50111" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger用户发送消息" name_chs="即时通信软件Yahoo Messenger用户发送消息" name_eng="Instant Messaging Software Yahoo Messenger User Sending Messages" visible="true"/><rule ruleid="50116" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户发送消息" name_chs="即时通信软件ICQ用户发送消息" name_eng="Instant Messaging Software ICQ User Sending Messages" visible="true"/><rule ruleid="50117" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户接收消息" name_chs="即时通信软件ICQ用户接收消息" name_eng="Instant Messaging Software ICQ User Receiving Messages" visible="true"/><rule ruleid="50114" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger传送文件" name_chs="即时通信软件Yahoo Messenger传送文件" name_eng="Instant Messaging Software Yahoo Messenger File Transmission" visible="true"/><rule ruleid="50115" enabled="true" group="99745885" action=" db  screen " name="即时通信软件Yahoo Messenger用户状态改变为离开" name_chs="即时通信软件Yahoo Messenger用户状态改变为离开" name_eng="Instant Messaging Software Yahoo Messenger User State Changed into &quot;Leave&quot;" visible="true"/><rule ruleid="30144" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.cmsd服务存在性UDP扫描探测" name_chs="Solaris rpc.cmsd服务存在性UDP扫描探测" name_eng="Solaris rpc.cmsd Service UDP Detection" visible="true"/><rule ruleid="50085" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN用户接收消息" name_chs="即时通信软件MSN用户接收消息" name_eng="Instant Messaging Software MSN User Receiving Messages" visible="true"/><rule ruleid="40066" enabled="true" group="145817685" action=" db  screen " name="TFTP服务客户端在服务器端创建文件" name_chs="TFTP服务客户端在服务器端创建文件" name_eng="TFTP Service Client File Creation On the Server" visible="true"/><rule ruleid="30226" enabled="true" group="95486045" action=" db  screen " name="Windows NT SMB建立连接" name_chs="Windows NT SMB建立连接" name_eng="Windows NT SMB Connection Establishment" visible="true" merge="[t28800,si,di]"/><rule ruleid="40075" enabled="true" group="233834570" action=" db  screen " name="超长ICMP ECHO报文攻击" name_chs="超长ICMP ECHO报文攻击" name_eng="Over-long ICMP ECHO Message" visible="true"/><rule ruleid="20818" enabled="true" group="78643498" action=" db  screen " name="3Com TFTP超长传输模式字段远程缓冲区溢出攻击" name_chs="3Com TFTP超长传输模式字段远程缓冲区溢出攻击" name_eng="3Com TFTP Over-Long Transporting Mode Field Remote Buffer Overflow" visible="true"/><rule ruleid="20819" enabled="true" group="212861226" action=" db  screen " name="Apache Tomcat JK Web Server Connector超长URL栈溢出攻击" name_chs="Apache Tomcat JK Web Server Connector超长URL栈溢出攻击" name_eng="Apache Tomcat JK Web Server Connector Over-Long URL Stack Overflow" visible="true"/><rule ruleid="20810" enabled="true" group="76546346" action=" db  screen " name="IMAP服务器畸形CRAM-MD5认证请求缓冲区溢出攻击" name_chs="IMAP服务器畸形CRAM-MD5认证请求缓冲区溢出攻击" name_eng="IMAP Server Malformed CRAM-MD5 Authentication Request Buffer Overflow" visible="true"/><rule ruleid="20811" enabled="true" group="83886378" action=" db  screen  drop " name="Microsoft Windows路由和远程访问服务溢出攻击（MS06-025）" name_chs="Microsoft Windows路由和远程访问服务溢出攻击（MS06-025）" name_eng="Microsoft Windows Route and Remote Access Service Buffer Overflow (MS06-025)" visible="true"/><rule ruleid="20812" enabled="true" group="99615786" action=" db  screen " name="MSN相册蠕虫发送photos.zip可疑文件" name_chs="MSN相册蠕虫发送photos.zip可疑文件" name_eng="MSN Album Worm Sending Suspicious photos.zip Files" visible="true"/><rule ruleid="20813" enabled="true" group="147849514" action=" db  screen " name="Kerberos 5 KAdminD服务程序远程栈溢出攻击" name_chs="Kerberos 5 KAdminD服务程序远程栈溢出攻击" name_eng="Kerberos 5 KAdminD Server Remote Stack Overflow" visible="true"/><rule ruleid="20814" enabled="true" group="138414122" action=" db  screen " name="MIT Kerberos 5 Telnet守护程序绕过认证访问攻击" name_chs="MIT Kerberos 5 Telnet守护程序绕过认证访问攻击" name_eng="MIT Kerberos 5 Telnet Daemon Authentication Bypass" visible="true"/><rule ruleid="20815" enabled="true" group="68159530" action=" db  screen " name="Microsoft IE恶意数据编码指令执行攻击" name_chs="Microsoft IE恶意数据编码指令执行攻击" name_eng="Microsoft IE Malicious Data Encoding Code Execution" visible="true"/><rule ruleid="20816" enabled="true" group="202375466" action=" db  screen " name="Netscape Enterprise HTTP协议Accept字段远程缓冲区溢出漏洞" name_chs="Netscape Enterprise HTTP协议Accept字段远程缓冲区溢出漏洞" name_eng="Netscape Enterprise HTTP Protocol Accept Field Remote Buffer Overflow" visible="true"/><rule ruleid="20817" enabled="true" group="68157738" action=" db  screen " name="Oracle 9iAS/10g应用服务器WEB缓冲远程堆溢出攻击" name_chs="Oracle 9iAS/10g应用服务器WEB缓冲远程堆溢出攻击" name_eng="Oracle 9iAS/10g Application Server WEB Buffer Remote Heap Overflow" visible="true"/><rule ruleid="10071" enabled="true" group="69206198" action=" db  screen " name="SalesLogix Eviewer slxweb.dll程序漏洞扫描探测" name_chs="SalesLogix Eviewer slxweb.dll程序漏洞扫描探测" name_eng="SalesLogix Eviewer slxweb.dll Vulnerability Detection" visible="true"/><rule ruleid="20143" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序tcsh" name_chs="通过Web服务访问Unix Shell解释程序tcsh" name_eng="Access to Unix Shell Interpreter tcsh via Web Service" visible="true"/><rule ruleid="20140" enabled="true" group="136315051" action=" db  screen " name="通过Web服务访问Unix Shell解释程序bash" name_chs="通过Web服务访问Unix Shell解释程序bash" name_eng="Access to Unix Shell Interpreter bash via Web Service" visible="true"/><rule ruleid="10072" enabled="true" group="337641623" action=" db  screen " name="利用3COM OfficeConnect Router Web管理接口漏洞拒绝服务攻击" name_chs="利用3COM OfficeConnect Router Web管理接口漏洞拒绝服务攻击" name_eng="Denial of Service via 3COM OfficeConnect Router Web Management Interface Vulnerability" visible="true"/><rule ruleid="10075" enabled="true" group="69206171" action=" db  screen " name="利用Netscape Servers search脚本漏洞远程拒绝服务攻击" name_chs="利用Netscape Servers search脚本漏洞远程拒绝服务攻击" name_eng="Remote Denial of Service via Netscape Servers search Script Vulnerability" visible="true"/><rule ruleid="30538" enabled="true" group="203423930" action=" db  screen " name="Xoops editor_registry.php脚本目录遍历攻击" name_chs="Xoops editor_registry.php脚本目录遍历攻击" name_eng="Xoops editor_registry.php Script Directory Traversal" visible="true"/><rule ruleid="10077" enabled="true" group="69206170" action=" db  screen " name="利用Behold! Software Counter.exe CGI漏洞拒绝服务攻击" name_chs="利用Behold! Software Counter.exe CGI漏洞拒绝服务攻击" name_eng="Denial of Service via Behold! Software Counter.exe CGI Vulnerability" visible="true"/><rule ruleid="10076" enabled="true" group="69214265" action=" db  screen " name="Behold! Software Counter.exe CGI程序漏洞扫描探测" name_chs="Behold! Software Counter.exe CGI程序漏洞扫描探测" name_eng="Behold! Software Counter.exe CGI Vulnerability Detection" visible="true"/><rule ruleid="10004" enabled="true" group="368082967" action=" db  screen " name="指令Modem挂起ICMP消息攻击" name_chs="指令Modem挂起ICMP消息攻击" name_eng="Signal Modem Hang ICMP Message" visible="true"/><rule ruleid="20148" enabled="true" group="69206187" action=" db  screen " name="利用Microsoft JET catalog_type.asp脚本漏洞远程执行命令" name_chs="利用Microsoft JET catalog_type.asp脚本漏洞远程执行命令" name_eng="Remote Code Execution via Microsoft JET catalog_type.asp Script Vulnerability" visible="true"/><rule ruleid="30539" enabled="true" group="136315066" action=" db  screen " name="Asterisk Web非授权访问Voicemail攻击" name_chs="Asterisk Web非授权访问Voicemail攻击" name_eng="Asterisk Web Voicemail Unauthorized Access" visible="true"/><rule ruleid="20780" enabled="true" group="99615019" action=" db  screen " name="Computer Associates MLink超长数据缓冲区溢出攻击" name_chs="Computer Associates MLink超长数据缓冲区溢出攻击" name_eng="Computer Associates MLink Over-Long Data Buffer Overflow" visible="true"/><rule ruleid="30536" enabled="true" group="203423930" action=" db  screen " name="Sugar Suite GLOBALS[sugarEntry]参数本地文件包含攻击" name_chs="Sugar Suite GLOBALS[sugarEntry]参数本地文件包含攻击" name_eng="Sugar Suite GLOBALS[sugarEntry] Parameter Local File Inclusion" visible="true"/><rule ruleid="20782" enabled="true" group="99615019" action=" db  screen " name="CA BrightStor ARCServe BackUp LGServer远程栈缓冲区溢出攻击" name_chs="CA BrightStor ARCServe BackUp LGServer远程栈缓冲区溢出攻击" name_eng="CA BrightStor ARCServe BackUp LGServer Remote Buffer Overflow" visible="true"/><rule ruleid="20783" enabled="true" group="203423915" action=" db  screen " name="Aigaion远程文件包含攻击" name_chs="Aigaion远程文件包含攻击" name_eng="Aigaion Remote File Inclusion" visible="true"/><rule ruleid="20784" enabled="true" group="203423915" action=" db  screen " name="ComVironment grab_globals.lib.php脚本远程文件包含攻击" name_chs="ComVironment grab_globals.lib.php脚本远程文件包含攻击" name_eng="ComVironment grab_globals.lib.php Script Remote File Inclusion" visible="true"/><rule ruleid="20785" enabled="true" group="203423915" action=" db  screen " name="Uberghey frontpage.php远程文件包含攻击" name_chs="Uberghey frontpage.php远程文件包含攻击" name_eng="Uberghey frontpage.php Remote File Inclusion" visible="true"/><rule ruleid="20786" enabled="true" group="203423915" action=" db  screen " name="PHPMyphorum frame.php远程文件包含攻击" name_chs="PHPMyphorum frame.php远程文件包含攻击" name_eng="PHPMyphorum frame.php Remote File Inclusion" visible="true"/><rule ruleid="30537" enabled="true" group="95422521" action=" db  screen " name="Microsoft Windows Server驱动内存信息泄露攻击" name_chs="Microsoft Windows Server驱动内存信息泄露攻击" name_eng="Microsoft Windows Server Driver Memory Information Disclosure" visible="true"/><rule ruleid="20788" enabled="true" group="69206186" action=" db  screen " name="Virtual Programming VP-ASP shopgiftregsearch.asp远程SQL注入攻击" name_chs="Virtual Programming VP-ASP shopgiftregsearch.asp远程SQL注入攻击" name_eng="Virtual Programming VP-ASP shopgiftregsearch.asp Remote SQL Injection" visible="true"/><rule ruleid="20789" enabled="true" group="203423915" action=" db  screen " name="Jshop Server远程文件包含攻击" name_chs="Jshop Server远程文件包含攻击" name_eng="Jshop Server Remote File Inclusion" visible="true"/><rule ruleid="30534" enabled="true" group="70256698" action=" db  screen " name="Home FTP Server远程目录遍历攻击" name_chs="Home FTP Server远程目录遍历攻击" name_eng="Home FTP Server Remote Directory Traversal" visible="true"/><rule ruleid="30224" enabled="true" group="69214266" action=" db  screen " name="OmniHTTPd visadmin.exe程序漏洞扫描探测" name_chs="OmniHTTPd visadmin.exe程序漏洞扫描探测" name_eng="OmniHTTPd visadmin.exe Vulnerability Detection" visible="true"/><rule ruleid="30243" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－FULLXMAS扫描" name_chs="服务器端口扫描－FULLXMAS扫描" name_eng="Server Port Scan - FULLXMAS Scan" visible="true"/><rule ruleid="30532" enabled="true" group="233834554" action=" db  screen " name="Arkeia Client默认root用户口令访问" name_chs="Arkeia Client默认root用户口令访问" name_eng="Arkeia Client Default root Account Password" visible="true"/><rule ruleid="30533" enabled="true" group="136315066" action=" db  screen " name="Webmin/Usermin远程访问任意文件攻击" name_chs="Webmin/Usermin远程访问任意文件攻击" name_eng="Webmin/Usermin Remote Arbitrary File Access" visible="true"/><rule ruleid="50140" enabled="true" group="233963613" action=" db  screen " name="PPLive网络电视流媒体播放(TCP)" name_chs="PPLive网络电视流媒体播放(TCP)" name_eng="PPLive Network TV Streaming Media Playing (TCP)" visible="true"/><rule ruleid="40771" enabled="true" group="99680330" action=" db  screen " name="Windows系统下Spyware Spytech下载安装程序" name_chs="Windows系统下Spyware Spytech下载安装程序" name_eng="Spyware Spytech Downloading Installer on Windows" visible="true"/><rule ruleid="30247" enabled="true" group="233840702" action=" db  screen " name="服务器端口扫描－XMAS扫描" name_chs="服务器端口扫描－XMAS扫描" name_eng="Server Port Scan - XMAS Scan" visible="true"/><rule ruleid="40224" enabled="true" group="69214246" action=" db  screen " name="perl.exe程序漏洞扫描探测" name_chs="perl.exe程序漏洞扫描探测" name_eng="perl.exe Vulnerability Detection" visible="true"/><rule ruleid="20568" enabled="true" group="203423919" action=" db  screen " name="LoudBlog backend_settings.php远程任意命令执行攻击" name_chs="LoudBlog backend_settings.php远程任意命令执行攻击" name_eng="LoudBlog backend_settings.php Remote Arbitrary Command Execution" visible="true"/><rule ruleid="20569" enabled="true" group="222300207" action=" db  screen " name="Oracle 9i/10g XML组件存储过程缓冲区溢出攻击" name_chs="Oracle 9i/10g XML组件存储过程缓冲区溢出攻击" name_eng="Oracle 9i/10g XML Component Stored Procedure Buffer Overflow" visible="true"/><rule ruleid="20564" enabled="true" group="99615019" action=" db  screen " name="Veritas NetBackup卷管理器守护程序溢出攻击" name_chs="Veritas NetBackup卷管理器守护程序溢出攻击" name_eng="Veritas NetBackup Volume Manager Daemon Buffer Overflow" visible="true"/><rule ruleid="20565" enabled="true" group="166725675" action=" db  screen " name="Nullsoft SHOUTcast文件请求远程格式串攻击" name_chs="Nullsoft SHOUTcast文件请求远程格式串攻击" name_eng="Nullsoft SHOUTcast File Request Remote Format String Vulnerability" visible="true"/><rule ruleid="20566" enabled="true" group="222300207" action=" db  screen " name="Oracle DBMS绕过登录访问控制攻击" name_chs="Oracle DBMS绕过登录访问控制攻击" name_eng="Oracle DBMS Login Access Control Bypass" visible="true"/><rule ruleid="20567" enabled="true" group="203423918" action=" db  screen " name="phpBB Style Changer\Viewer远程SQL注入攻击" name_chs="phpBB Style Changer\Viewer远程SQL注入攻击" name_eng="phpBB Style Changer\Viewer Remote SQL Injection" visible="true"/><rule ruleid="20560" enabled="true" group="136315055" action=" db  screen " name="CuteNews show_archives.php远程任意命令执行攻击" name_chs="CuteNews show_archives.php远程任意命令执行攻击" name_eng="CuteNews show_archives.php Remote Arbitrary Command Execution" visible="true"/><rule ruleid="20561" enabled="true" group="203423919" action=" db  screen " name="CubeCart orderSuccess.inc.php远程任意命令执行攻击" name_chs="CubeCart orderSuccess.inc.php远程任意命令执行攻击" name_eng="CubeCart orderSuccess.inc.php Remote Arbitrary Command Execution" visible="true"/><rule ruleid="20562" enabled="true" group="203423919" action=" db  screen " name="Valdersoft Shopping Cart远程任意命令执行攻击" name_chs="Valdersoft Shopping Cart远程任意命令执行攻击" name_eng="Valdersoft Shopping Cart Remote Arbitrary Command Execution" visible="true"/><rule ruleid="20563" enabled="true" group="99616814" action=" db  screen " name="Microsoft Windows图形渲染引擎WMF格式文件执行指令攻击" name_chs="Microsoft Windows图形渲染引擎WMF格式文件执行指令攻击" name_eng="Microsoft Windows Graphics Rendering Engine WMF Format File Code Execution" visible="true"/><rule ruleid="30051" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.admind服务存在性UDP扫描探测" name_chs="Solaris rpc.admind服务存在性UDP扫描探测" name_eng="Solaris rpc.admind Service UDP Detection" visible="true"/><rule ruleid="30050" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.rstatd服务存在性UDP扫描探测" name_chs="Solaris rpc.rstatd服务存在性UDP扫描探测" name_eng="Solaris rpc.rstatd Service UDP Detection" visible="true"/><rule ruleid="30219" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage配置文件registrations.htm获取服务器信息" name_chs="访问Frontpage配置文件registrations.htm获取服务器信息" name_eng="Server Information Disclosure from Frontpage Config File registrations.htm" visible="true"/><rule ruleid="30218" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage配置文件register.txt获取服务器信息" name_chs="访问Frontpage配置文件register.txt获取服务器信息" name_eng="Server Information Disclosure from Frontpage Config File register.txt" visible="true"/><rule ruleid="40708" enabled="true" group="99618887" action=" db  screen " name="Windows系统下彩虹兽人木马通信" name_chs="Windows系统下彩虹兽人木马通信" name_eng="Trojan Bifrost Communication on Windows" visible="true"/><rule ruleid="40709" enabled="true" group="99618891" action=" db  screen " name="Windows系统下byshell木马通信" name_chs="Windows系统下byshell木马通信" name_eng="Trojan byshell Communication on Windows" visible="true"/><rule ruleid="40706" enabled="true" group="99618891" action=" db  screen " name="Windows系统下无赖小子木马通信" name_chs="Windows系统下无赖小子木马通信" name_eng="Trojan Way2.5 Communication on Windows" visible="true"/><rule ruleid="30212" enabled="true" group="69206202" action=" db  screen " name="利用iCat Managers carbo.dll脚本漏洞远程遍历目录" name_chs="利用iCat Managers carbo.dll脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via iCat Managers carbo.dll Script Vulnerability" visible="true"/><rule ruleid="40704" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Mithril木马通信" name_chs="Windows系统下Mithril木马通信" name_eng="Trojan Mithril Communication on Windows" visible="true"/><rule ruleid="40705" enabled="true" group="99618895" action=" db  screen " name="Windows系统下网络神偷木马通信" name_chs="Windows系统下网络神偷木马通信" name_eng="Trojan NetThief Communication on Windows" visible="true"/><rule ruleid="30217" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage配置文件orders.txt获取服务器信息" name_chs="访问Frontpage配置文件orders.txt获取服务器信息" name_eng="Server Information Disclosure from Frontpage Config File orders.txt" visible="true"/><rule ruleid="30216" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage .cnf配置文件获取服务器信息" name_chs="访问Frontpage .cnf配置文件获取服务器信息" name_eng="Server Information Disclosure from Frontpage .cnf File" visible="true"/><rule ruleid="30215" enabled="true" group="69206197" action=" db  screen " name="通过Web服务访问site.csc文件获取数据信息" name_chs="通过Web服务访问site.csc文件获取数据信息" name_eng="Data Disclosure from site.csc file via Web Service" visible="true"/><rule ruleid="40701" enabled="true" group="99618891" action=" db  screen " name="Windows系统下远程控制任我行木马通信" name_chs="Windows系统下远程控制任我行木马通信" name_eng="Remote Control Software Trojan.LetMein.a Communication on Windows" visible="true"/><rule ruleid="30057" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.ypupdated服务存在性UDP扫描探测" name_chs="Solaris rpc.ypupdated服务存在性UDP扫描探测" name_eng="Solaris rpc.ypupdated Service UDP Detection" visible="true"/><rule ruleid="30220" enabled="true" group="69206201" action=" db  screen " name="访问Frontpage配置文件service.stp获取服务器信息" name_chs="访问Frontpage配置文件service.stp获取服务器信息" name_eng="Server Information Disclosure from Frontpage Config File service.stp" visible="true"/><rule ruleid="30056" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.ypserv服务存在性UDP扫描探测" name_chs="Solaris rpc.ypserv服务存在性UDP扫描探测" name_eng="Solaris rpc.ypserv Service UDP Detection" visible="true"/><rule ruleid="40382" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Mstream主控端探测分布端" name_chs="DDOS工具Mstream主控端探测分布端" name_eng="DDOS Tool Mstream Console and Distributed End Detection" visible="true"/><rule ruleid="40383" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Mstream分布端回应主控端" name_chs="DDOS工具Mstream分布端回应主控端" name_eng="DDOS Tool Mstream Distributed End Responding to the Console" visible="true"/><rule ruleid="20368" enabled="true" group="233832751" action=" db  screen  drop " name="Real Networks Helix Universal Server远程缓冲区溢出攻击" name_chs="Real Networks Helix Universal Server远程缓冲区溢出攻击" name_eng="Real Networks Helix Universal Server Remote Buffer Overflow" visible="true"/><rule ruleid="40381" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Mstream主分布端连接分布端" name_chs="DDOS工具Mstream主分布端连接分布端" name_eng="Connection Between DDOS Tool Mstream Main Distributed End and Distributed End" visible="true"/><rule ruleid="40387" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Trinoo主控端发送指令" name_chs="DDOS工具Trinoo主控端发送指令" name_eng="DDOS Tool Trinoo Console Sending Command" visible="true"/><rule ruleid="40384" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Mstream分布端回应主控端" name_chs="DDOS工具Mstream分布端回应主控端" name_eng="DDOS Tool Mstream Distributed End Responding to the Console" visible="true"/><rule ruleid="50089" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN传送文件企图" name_chs="即时通信软件MSN传送文件企图" name_eng="Instant Messaging Software MSN Sending File Attempt" visible="true"/><rule ruleid="20363" enabled="true" group="83886383" action=" db  screen  drop " name="Microsoft Windows DCOM RPC接口长主机名远程缓冲区溢出攻击" name_chs="Microsoft Windows DCOM RPC接口长主机名远程缓冲区溢出攻击" name_eng="Microsoft Windows DCOM RPC Interface Long Host Name Remote Buffer Overflow" visible="true" merge="[t7200,si]"/><rule ruleid="20360" enabled="true" group="136315051" action=" db  screen " name="利用HappyMall E-Commerce normal_html.cgi脚本漏洞远程执行命令" name_chs="利用HappyMall E-Commerce normal_html.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via HappyMall E-Commerce normal_html.cgi Script Vulnerability" visible="true"/><rule ruleid="20361" enabled="true" group="203423915" action=" db  screen " name="利用shoutbox脚本漏洞远程执行命令" name_chs="利用shoutbox脚本漏洞远程执行命令" name_eng="Remote Code Execution via shoutbox Script Vulnerability" visible="true"/><rule ruleid="20366" enabled="true" group="99615791" action=" db  screen " name="Windows系统下SDBot蠕虫传播操作" name_chs="Windows系统下SDBot蠕虫传播操作" name_eng="Worm SDBot Propagation on Windows" visible="true"/><rule ruleid="20367" enabled="true" group="99680317" action=" db  screen " name="Windows icmpsendecho函数发送ICMP包" name_chs="Windows icmpsendecho函数发送ICMP包" name_eng="Windows icmpsendecho Sending ICMP Packet" visible="false" merge="[t28800,si]"/><rule ruleid="20365" enabled="true" group="83887151" action=" db  screen  drop " name="Windows系统下MSBLAST（冲击波）蠕虫传播" name_chs="Windows系统下MSBLAST（冲击波）蠕虫传播" name_eng="Worm MSBLAST on Windows" visible="true" merge="[t300,si]"/><rule ruleid="30459" enabled="true" group="69214266" action=" db  screen " name="Alt-N WebAdmin WebAdmin.dll脚本漏洞扫描探测" name_chs="Alt-N WebAdmin WebAdmin.dll脚本漏洞扫描探测" name_eng="Alt-N WebAdmin WebAdmin.dll Script Vulnerability Detection" visible="true"/><rule ruleid="30458" enabled="true" group="69206198" action=" db  screen " name="利用AN HTTPd count.pl脚本漏洞遍历目录" name_chs="利用AN HTTPd count.pl脚本漏洞遍历目录" name_eng="Directory Traversal via AN HTTPd count.pl Script Vulnerability" visible="true"/><rule ruleid="30109" enabled="true" group="136315066" action=" db  screen " name="Roar Smith info2www脚本漏洞扫描探测" name_chs="Roar Smith info2www脚本漏洞扫描探测" name_eng="Roar Smith info2www Script Vulnerability Detection" visible="true"/><rule ruleid="30108" enabled="true" group="136315062" action=" db  screen " name="Miva htmlscript脚本漏洞扫描探测" name_chs="Miva htmlscript脚本漏洞扫描探测" name_eng="Miva htmlscript Script Vulnerability Detection" visible="true"/><rule ruleid="30455" enabled="true" group="69208122" action=" db  screen " name="利用Sambar Server CGI程序远程获取信息攻击" name_chs="利用Sambar Server CGI程序远程获取信息攻击" name_eng="Information Disclosure via Sambar Server CGI Program" visible="true"/><rule ruleid="30106" enabled="true" group="136315066" action=" db  screen " name="IRIX handler脚本漏洞扫描探测" name_chs="IRIX handler脚本漏洞扫描探测" name_eng="IRIX handler Script Vulnerability Detection" visible="true"/><rule ruleid="30457" enabled="true" group="69206202" action=" db  screen " name="利用CGI脚本对Sambar Server进行目录遍历攻击" name_chs="利用CGI脚本对Sambar Server进行目录遍历攻击" name_eng="Directory Traversal against Sambar Server via CGI Script" visible="true"/><rule ruleid="30456" enabled="true" group="69214265" action=" db  screen " name="Sambar Server目录遍历脚本漏洞扫描探测" name_chs="Sambar Server目录遍历脚本漏洞扫描探测" name_eng="Sambar Server Directory Traversal Script Vulnerability Detection" visible="true"/><rule ruleid="30103" enabled="true" group="136315062" action=" db  screen " name="利用Feartech ftp.pl脚本漏洞远程获取主机目录攻击" name_chs="利用Feartech ftp.pl脚本漏洞远程获取主机目录攻击" name_eng="Remote Host Directory Disclosure via Feartech ftp.pl Script Vulnerability" visible="true"/><rule ruleid="30102" enabled="true" group="136315066" action=" db  screen " name="FormMail formmail.pl脚本漏洞扫描探测" name_chs="FormMail formmail.pl脚本漏洞扫描探测" name_eng="FormMail formmail.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30453" enabled="true" group="136323126" action=" db  screen " name="Logbook logbook.pl脚本漏洞扫描探测" name_chs="Logbook logbook.pl脚本漏洞扫描探测" name_eng="Logbook logbook.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30100" enabled="true" group="136315066" action=" db  screen " name="CVSWeb cvsweb.cgi脚本漏洞扫描探测" name_chs="CVSWeb cvsweb.cgi脚本漏洞扫描探测" name_eng="CVSWeb cvsweb.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="10134" enabled="true" group="99616799" action=" db  screen " name="Microsoft Windows即插即用功能远程拒绝服务攻击" name_chs="Microsoft Windows即插即用功能远程拒绝服务攻击" name_eng="Microsoft Windows Plug and Play Feature Remote Denial of Service" visible="true"/><rule ruleid="20536" enabled="true" group="76546347" action=" db  screen " name="IMAP服务器STATUS命令超长参数远程缓冲区溢出攻击" name_chs="IMAP服务器STATUS命令超长参数远程缓冲区溢出攻击" name_eng="IMAP Server STATUS Command Over-long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20535" enabled="true" group="156238119" action=" db  screen  drop " name="HP-UX LPD远程命令执行攻击" name_chs="HP-UX LPD远程命令执行攻击" name_eng="HP-UX LPD Remote Command Execution" visible="true"/><rule ruleid="40638" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Blackmal.C蠕虫病毒邮件" name_chs="SMTP服务发送W32.Blackmal.C蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Blackmal.C" visible="true"/><rule ruleid="20534" enabled="true" group="76546343" action=" db  screen " name="Mercury/32 IMAP RENAME命令远程缓冲区溢出攻击" name_chs="Mercury/32 IMAP RENAME命令远程缓冲区溢出攻击" name_eng="Mercury/32 IMAP RENAME Command Remote Buffer Overflow" visible="true"/><rule ruleid="20533" enabled="true" group="203423919" action=" db  screen " name="My Little Forum search.php CGI脚本SQL注入攻击" name_chs="My Little Forum search.php CGI脚本SQL注入攻击" name_eng="My Little Forum search.php CGI Script SQL Injection" visible="true"/><rule ruleid="40630" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Beagle.AO@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Beagle.AO@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Beagle.AO@mm" visible="true"/><rule ruleid="40631" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.Q蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.Q蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.Q" visible="true"/><rule ruleid="40636" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.S/T蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.S/T蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.S/T" visible="true"/><rule ruleid="40637" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Mydoom.V蠕虫病毒邮件" name_chs="SMTP服务发送Mydoom.V蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Mydoom.V" visible="true"/><rule ruleid="40634" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Neveg蠕虫病毒邮件" name_chs="SMTP服务发送W32.Neveg蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Neveg" visible="true"/><rule ruleid="40635" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Bugbear.M蠕虫病毒邮件" name_chs="SMTP服务发送W32.Bugbear.M蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Bugbear.M" visible="true"/><rule ruleid="20216" enabled="true" group="136323125" action=" db  screen " name="CSM Alibaba Web Server get32.exe脚本漏洞扫描探测" name_chs="CSM Alibaba Web Server get32.exe脚本漏洞扫描探测" name_eng="CSM Alibaba Web Server get32.exe Script Vulnerability Detection" visible="true"/><rule ruleid="20217" enabled="true" group="203423915" action=" db  screen " name="利用Web Portal customize.php脚本漏洞远程执行命令" name_chs="利用Web Portal customize.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Web Portal customize.php Script Vulnerability" visible="true"/><rule ruleid="20214" enabled="true" group="203423915" action=" db  screen " name="利用FreeNews aff_news.php脚本漏洞远程执行命令" name_chs="利用FreeNews aff_news.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via FreeNews aff_news.php Script Vulnerability" visible="true"/><rule ruleid="20215" enabled="true" group="203423915" action=" db  screen " name="利用FreeNews screen.php脚本漏洞远程执行命令" name_chs="利用FreeNews screen.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via FreeNews screen.php Script Vulnerability" visible="true"/><rule ruleid="20212" enabled="true" group="203431994" action=" db  screen " name="FreeNews aff_news.php脚本漏洞扫描探测" name_chs="FreeNews aff_news.php脚本漏洞扫描探测" name_eng="FreeNews aff_news.php Script Vulnerability Detection" visible="true"/><rule ruleid="20213" enabled="true" group="203431994" action=" db  screen " name="FreeNews screen.php脚本漏洞扫描探测" name_chs="FreeNews screen.php脚本漏洞扫描探测" name_eng="FreeNews screen.php Script Vulnerability Detection" visible="true"/><rule ruleid="20210" enabled="true" group="136315051" action=" db  screen " name="利用Talentsoft Web+例子脚本执行命令攻击" name_chs="利用Talentsoft Web+例子脚本执行命令攻击" name_eng="Remote Code Execution via Talentsoft Web+ Sample Script" visible="true"/><rule ruleid="20211" enabled="true" group="203423914" action=" db  screen " name="Phorum 3.0.7 auth.php3脚本漏洞扫描利用" name_chs="Phorum 3.0.7 auth.php3脚本漏洞扫描利用" name_eng="Phorum 3.0.7 auth.php3 Script Vulnerability Detection" visible="true"/><rule ruleid="50084" enabled="true" group="99745885" action=" db  screen " name="即时通信软件MSN用户发送消息" name_chs="即时通信软件MSN用户发送消息" name_eng="Instant Messaging Software MSN User Sending Messages" visible="true"/><rule ruleid="20530" enabled="true" group="203423915" action=" db  screen " name="MyBulletinBoard 多个CGI脚本SQL注入攻击" name_chs="MyBulletinBoard 多个CGI脚本SQL注入攻击" name_eng="MyBulletinBoard multiple CGI Scripts SQL Injection" visible="true"/><rule ruleid="20218" enabled="true" group="203423915" action=" db  screen " name="利用Web Portal index.php脚本漏洞远程执行命令" name_chs="利用Web Portal index.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Web Portal index.php Script Vulnerability" visible="true"/><rule ruleid="20219" enabled="true" group="166723887" action=" db  screen " name="OpenSSL远程缓冲区溢出攻击" name_chs="OpenSSL远程缓冲区溢出攻击" name_eng="OpenSSL Remote Buffer Overflow" visible="true"/><rule ruleid="40702" enabled="true" group="99618887" action=" db  screen " name="Windows系统下Pennumbra木马通信" name_chs="Windows系统下Pennumbra木马通信" name_eng="Pennumbra Communication on Windows " visible="true"/><rule ruleid="40703" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Spook 6.0木马通信" name_chs="Windows系统下Spook 6.0木马通信" name_eng="Trojan Spook 6.0 Communication on Windows" visible="true"/><rule ruleid="40526" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Intruzzo木马通信" name_chs="Windows系统下Intruzzo木马通信" name_eng="Trojan Intruzzo Communication on Windows" visible="true"/><rule ruleid="40527" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Kid Terror木马通信" name_chs="Windows系统下Kid Terror木马通信" name_eng="Trojan Kid Terror Communication on Windows" visible="true"/><rule ruleid="40524" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Insane Network木马通信" name_chs="Windows系统下Insane Network木马通信" name_eng="Trojan Insane Network Communication on Windows" visible="true"/><rule ruleid="40525" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Intruder木马通信" name_chs="Windows系统下Intruder木马通信" name_eng="Trojan Intruder Communication on Windows" visible="true"/><rule ruleid="40522" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Infector木马通信" name_chs="Windows系统下Infector木马通信" name_eng="Trojan Infector Communication on Windows" visible="true"/><rule ruleid="40523" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Infra木马通信" name_chs="Windows系统下Infra木马通信" name_eng="Trojan Infra Communication on Windows" visible="true"/><rule ruleid="40520" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下HydroLeak木马通信" name_chs="Windows系统下HydroLeak木马通信" name_eng="Trojan HydroLeak Communication on Windows" visible="true"/><rule ruleid="40521" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下InCommand木马通信" name_chs="Windows系统下InCommand木马通信" name_eng="Trojan InCommand Communication on Windows" visible="true"/><rule ruleid="40528" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Konik木马通信" name_chs="Windows系统下Konik木马通信" name_eng="Trojan Konik Communication on Windows" visible="true"/><rule ruleid="40529" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Kuang木马通信" name_chs="Windows系统下Kuang木马通信" name_eng="Trojan Kuang Communication on Windows" visible="true"/><rule ruleid="30076" enabled="true" group="136315062" action=" db  screen " name="通过Web服务执行finger程序" name_chs="通过Web服务执行finger程序" name_eng="finger Program Execution via Web Service" visible="true"/><rule ruleid="30075" enabled="true" group="204480570" action=" db  screen " name="漏洞扫描器ADM-FTP扫描FTP服务" name_chs="漏洞扫描器ADM-FTP扫描FTP服务" name_eng="ADM-FTP Scanner Scanning FTP Service" visible="true"/><rule ruleid="30073" enabled="true" group="233840697" action=" db  screen " name="网络嗅探工具Sniffer Pro/NetXRay PING操作" name_chs="网络嗅探工具Sniffer Pro/NetXRay PING操作" name_eng="Sniffer Pro/NetXRay PING Operation" visible="true"/><rule ruleid="20106" enabled="true" group="150995247" action=" db  screen " name="Solaris rpc.snmpXdmid远程缓冲区溢出攻击" name_chs="Solaris rpc.snmpXdmid远程缓冲区溢出攻击" name_eng="Solaris rpc.snmpXdmid Remote Buffer Overflow" visible="true"/><rule ruleid="50127" enabled="true" group="99745885" action=" db  screen " name="网络游戏星际争霸（Starcraft）网络对战" name_chs="网络游戏星际争霸（Starcraft）网络对战" name_eng=" Online Game &quot;Starcraft&quot; Online Fight" visible="true"/><rule ruleid="50126" enabled="true" group="99745885" action=" db  screen " name="网络游戏反恐精英（CS）网络对战" name_chs="网络游戏反恐精英（CS）网络对战" name_eng="Online Game CS Online Fight" visible="true"/><rule ruleid="50125" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ发现非法信息" name_chs="即时通信软件ICQ发现非法信息" name_eng="Instant Messaging Software ICQ Illegal Information" visible="true"/><rule ruleid="10036" enabled="false" group="99616794" action=" db  screen " name="mstream ACK/FIN小数据包洪流拒绝服务攻击" name_chs="mstream ACK/FIN小数据包洪流拒绝服务攻击" name_eng="mstream ACK/FIN Small Packets Flood Denial of Service" visible="true"/><rule ruleid="50123" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户视频聊天" name_chs="即时通信软件ICQ用户视频聊天" name_eng="Instant Messaging Software ICQ User Video Chatting" visible="true"/><rule ruleid="50122" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ用户音频聊天" name_chs="即时通信软件ICQ用户音频聊天" name_eng="Instant Messaging Software ICQ User Audio Chatting" visible="true"/><rule ruleid="50121" enabled="true" group="233963613" action=" db  screen " name="即时通信软件ICQ传送文件企图" name_chs="即时通信软件ICQ传送文件企图" name_eng="Instant Messaging Software ICQ Sending File Attempt" visible="true"/><rule ruleid="50129" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具BitTorrent通过UDP协议获取文件信息" name_chs="P2P文件共享工具BitTorrent通过UDP协议获取文件信息" name_eng="P2P File Sharing Tool BitTorrent Obtainning Files over UDP Protocol" visible="true"/><rule ruleid="50128" enabled="true" group="99745885" action=" db  screen " name="网络游戏魔兽争霸（Warcraft）网络对战" name_chs="网络游戏魔兽争霸（Warcraft）网络对战" name_eng="Online Game &quot;Warcraft&quot;" visible="true"/><rule ruleid="30252" enabled="true" group="347111482" action=" db  screen " name="TFTP服务获取Cisco IP Phone 7960配置文件攻击" name_chs="TFTP服务获取Cisco IP Phone 7960配置文件攻击" name_eng="Cisco IP Phone 7960 Configuration File Disclosure via TFTP Service" visible="true"/><rule ruleid="50097" enabled="true" group="233898077" action=" db  screen " name="DHCP服务器Offer配置信息操作" name_chs="DHCP服务器Offer配置信息操作" name_eng="DHCP Server Offer Information Configuration Operation" visible="true"/><rule ruleid="50096" enabled="true" group="99745885" action=" db  screen " name="网络游戏QUAKE客户端连接服务器" name_chs="网络游戏QUAKE客户端连接服务器" name_eng="Connection from Client to Server of Online Game &quot;QUAKE&quot;" visible="true"/><rule ruleid="40774" enabled="true" group="99680330" action=" db  screen " name="Windows系统下Adware P2PNetworking网络通信" name_chs="Windows系统下Adware P2PNetworking网络通信" name_eng="Windows Adware P2PNetworking Network Communication" visible="true"/><rule ruleid="50095" enabled="true" group="99745885" action=" db  screen " name="即时通信软件QQ用户登录（UDP）" name_chs="即时通信软件QQ用户登录（UDP）" name_eng="Instant Messaging Software QQ User Login (UDP)" visible="true"/><rule ruleid="40772" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware Superbar下载安装程序" name_chs="Windows系统下Adware Superbar下载安装程序" name_eng="Adware Superbar Downloading Installer on Windows" visible="true"/><rule ruleid="10062" enabled="true" group="69206167" action=" db  screen " name="利用WebSphere helpout.exe程序漏洞拒绝服务攻击" name_chs="利用WebSphere helpout.exe程序漏洞拒绝服务攻击" name_eng="Denial of Service via WebSphere helpout.exe Vulnerability" visible="true"/><rule ruleid="10063" enabled="true" group="99616795" action=" db  screen " name="Microsoft Windows 2000域控制器拒绝服务攻击" name_chs="Microsoft Windows 2000域控制器拒绝服务攻击" name_eng="Microsoft Windows 2000 Domain Controller Denial of Service" visible="true"/><rule ruleid="10060" enabled="false" group="88082463" action=" db  screen " name="Oracle 9i TNS单字节包拒绝服务攻击" name_chs="Oracle 9i TNS单字节包拒绝服务攻击" name_eng="Oracle 9i TNS Off-by-one Denial of Service" visible="true"/><rule ruleid="10061" enabled="true" group="73402395" action=" db  screen " name="Microsoft Windows 2000 RPC服务远程拒绝服务攻击" name_chs="Microsoft Windows 2000 RPC服务远程拒绝服务攻击" name_eng="Microsoft Windows 2000 RPC Service Remote Denial of Service" visible="true"/><rule ruleid="10066" enabled="true" group="222300191" action=" db  screen " name="Oracle TNS Listener Service_CurLoad远程拒绝服务攻击" name_chs="Oracle TNS Listener Service_CurLoad远程拒绝服务攻击" name_eng="Oracle TNS Listener Service_CurLoad Remote Denial of Service" visible="true"/><rule ruleid="10067" enabled="true" group="68159515" action=" db  screen " name="Netscape Enterprise Server REVLOG请求远程拒绝服务攻击" name_chs="Netscape Enterprise Server REVLOG请求远程拒绝服务攻击" name_eng="Netscape Enterprise Server REVLOG Request Remote Denial of Service" visible="true"/><rule ruleid="20179" enabled="true" group="203423914" action=" db  screen " name="Ultimate PHP Board远程管理页面admin_forum.php访问" name_chs="Ultimate PHP Board远程管理页面admin_forum.php访问" name_eng="Access to Ultimate PHP Board Remote Admin Page admin_forum.php" visible="true"/><rule ruleid="20178" enabled="true" group="203423914" action=" db  screen " name="Ultimate PHP Board远程管理页面admin_cat.php访问" name_chs="Ultimate PHP Board远程管理页面admin_cat.php访问" name_eng="Access to Ultimate PHP Board Remote Admin Page admin_cat.php" visible="true"/><rule ruleid="20177" enabled="true" group="203423914" action=" db  screen " name="Ultimate PHP Board远程管理页面admin_config.php访问" name_chs="Ultimate PHP Board远程管理页面admin_config.php访问" name_eng="Access to Ultimate PHP Board Remote Admin Page admin_config.php" visible="true"/><rule ruleid="20176" enabled="true" group="203423914" action=" db  screen " name="Ultimate PHP Board远程管理脚本admin_members.php访问" name_chs="Ultimate PHP Board远程管理脚本admin_members.php访问" name_eng="Access to Ultimate PHP Board Remote Admin Script admin_members.php" visible="true"/><rule ruleid="10068" enabled="true" group="202377243" action=" db  screen " name="Allaire JRun Servlet畸形请求远程拒绝服务攻击" name_chs="Allaire JRun Servlet畸形请求远程拒绝服务攻击" name_eng="Allaire JRun Servlet Malformed Requests Remote Denial of Service" visible="true"/><rule ruleid="10069" enabled="true" group="203423899" action=" db  screen " name="Unify eWave ServletExec远程拒绝服务攻击" name_chs="Unify eWave ServletExec远程拒绝服务攻击" name_eng="Unify eWave ServletExec Remote Denial of Service" visible="true"/><rule ruleid="20173" enabled="true" group="68157739" action=" db  screen " name="Savant Webserver cgitest.exe远程缓冲区溢出攻击" name_chs="Savant Webserver cgitest.exe远程缓冲区溢出攻击" name_eng="Savant Webserver cgitest.exe Remote Buffer Overflow" visible="true"/><rule ruleid="20172" enabled="true" group="203423915" action=" db  screen " name="利用vBulletin Calendar.php脚本漏洞远程执行命令" name_chs="利用vBulletin Calendar.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via vBulletin Calendar.php Script Vulnerability" visible="true"/><rule ruleid="20171" enabled="true" group="68157615" action=" db  screen  drop " name="Microsoft IIS 4.0/5.0 CGI文件名错误解码攻击" name_chs="Microsoft IIS 4.0/5.0 CGI文件名错误解码攻击" name_eng="Microsoft IIS 4.0/5.0 CGI Filename Incorrect Decoding" visible="true"/><rule ruleid="20779" enabled="true" group="166723883" action=" db  screen " name="Squid Cache FTP代理URL缓冲区溢出攻击" name_chs="Squid Cache FTP代理URL缓冲区溢出攻击" name_eng="Squid Cache FTP Proxy URL Buffer Overflow" visible="true"/><rule ruleid="20778" enabled="true" group="69206315" action=" db  screen " name="Microsoft SQLXML ISAPI远程缓冲区溢出攻击" name_chs="Microsoft SQLXML ISAPI远程缓冲区溢出攻击" name_eng="Microsoft SQLXML ISAPI Remote Buffer Overflow" visible="true"/><rule ruleid="20775" enabled="true" group="69206314" action=" db  screen " name="SAP DB Webagent远程缓冲区溢出攻击" name_chs="SAP DB Webagent远程缓冲区溢出攻击" name_eng="SAP DB Webagent Remote Buffer Overflow" visible="true"/><rule ruleid="20774" enabled="true" group="142608427" action=" db  screen " name="bsmtpd远程命令注入攻击" name_chs="bsmtpd远程命令注入攻击" name_eng="bsmtpd Remote Command Injection" visible="true"/><rule ruleid="20777" enabled="true" group="166723883" action=" db  screen " name="Fake Identd远程缓冲区溢出攻击" name_chs="Fake Identd远程缓冲区溢出攻击" name_eng="Fake Identd Remote Buffer Overflow" visible="true"/><rule ruleid="20776" enabled="true" group="69206314" action=" db  screen " name="Kerio MailServer远程用户名缓冲区溢出攻击" name_chs="Kerio MailServer远程用户名缓冲区溢出攻击" name_eng="Kerio MailServer Username Remote Buffer Overflow" visible="true"/><rule ruleid="20771" enabled="true" group="203423915" action=" db  screen " name="GrayCMS error.php远程文件包含攻击" name_chs="GrayCMS error.php远程文件包含攻击" name_eng="GrayCMS error.php Remote File Inclusion" visible="true"/><rule ruleid="20770" enabled="true" group="69206186" action=" db  screen " name="MetaCart2 intCatalogID参数远程SQL注入攻击" name_chs="MetaCart2 intCatalogID参数远程SQL注入攻击" name_eng="MetaCart2 intCatalogID Parameter Remote SQL Injection" visible="true"/><rule ruleid="20773" enabled="true" group="136315050" action=" db  screen " name="IceCast XSL远程绕过认证攻击" name_chs="IceCast XSL远程绕过认证攻击" name_eng="IceCast XSL Remote Authentication Bypass" visible="true"/><rule ruleid="20772" enabled="true" group="272631850" action=" db  screen " name="Bay Technical Associates RPC3 Telnet访问认证绕过攻击" name_chs="Bay Technical Associates RPC3 Telnet访问认证绕过攻击" name_eng="Bay Technical Associates RPC3 Telnet Authentication Bypass" visible="true"/><rule ruleid="30429" enabled="true" group="70256694" action=" db  screen " name="BisonFTP远程获取信息攻击" name_chs="BisonFTP远程获取信息攻击" name_eng="BisonFTP Remote Information Disclosure" visible="true"/><rule ruleid="70051" enabled="true" group="138414127" action="" name="TELNET服务TTYPROMPT环境变量内部事件" name_chs="TELNET服务TTYPROMPT环境变量内部事件" name_eng="Internal Event of Environmental Variable TTYPROMPT for TELNET Service " visible="false"/><rule ruleid="30146" enabled="true" group="69214270" action=" db  screen " name="Microsoft IIS 5.0 .printer ISAPI扩展映射存在性扫描探测" name_chs="Microsoft IIS 5.0 .printer ISAPI扩展映射存在性扫描探测" name_eng="Microsoft IIS 5.0 .printer ISAPI Extension Mapping Detection" visible="true"/><rule ruleid="20519" enabled="true" group="99615019" action=" db  screen " name="CA BrightStor ARCserve Backup for MS SQL缓冲区溢出攻击" name_chs="CA BrightStor ARCserve Backup for MS SQL缓冲区溢出攻击" name_eng="CA BrightStor ARCserve Backup for MS SQL Buffer Overflow" visible="true"/><rule ruleid="20518" enabled="true" group="203423919" action=" db  screen " name="MySQL Eventum远程SQL注入攻击" name_chs="MySQL Eventum远程SQL注入攻击" name_eng="MySQL Eventum Script SQL Injection" visible="true"/><rule ruleid="10118" enabled="true" group="233834527" action=" db  screen  drop " name="UDP畸形数据包PING-PONG拒绝服务攻击" name_chs="UDP畸形数据包PING-PONG拒绝服务攻击" name_eng="Malformed UDP Packet PING-PONG Denial of Service" visible="true"/><rule ruleid="10119" enabled="true" group="233834527" action=" db  screen  drop " name="IGMP畸形包拒绝服务攻击" name_chs="IGMP畸形包拒绝服务攻击" name_eng="Malformed IGMP Packet Denial of Service" visible="true"/><rule ruleid="20511" enabled="true" group="98566447" action=" db  screen " name="Microsoft Outlook Express NNTP LIST命令响应解析溢出攻击" name_chs="Microsoft Outlook Express NNTP LIST命令响应解析溢出攻击" name_eng="Microsoft Outlook Express NNTP LIST Command Response Resolution Overflow" visible="true"/><rule ruleid="10117" enabled="true" group="233834527" action=" db  screen  drop " name="IP畸形分片包拒绝服务攻击" name_chs="IP畸形分片包拒绝服务攻击" name_eng="Malformed IP Fragmented Packet Denial of Service" visible="true"/><rule ruleid="20513" enabled="true" group="203423915" action=" db  screen " name="PHPAuction adsearch.php/viewnews.php远程SQL注入攻击" name_chs="PHPAuction adsearch.php/viewnews.php远程SQL注入攻击" name_eng="PHPAuction adsearch.php/viewnews.php Remote SQL Injection" visible="true"/><rule ruleid="20512" enabled="true" group="203423919" action=" db  screen " name="UBBThreads download.php远程SQL注入攻击" name_chs="UBBThreads download.php远程SQL注入攻击" name_eng="UBBThreads download.php Remote SQL Injection" visible="true"/><rule ruleid="10112" enabled="true" group="68159511" action=" db  screen " name="Microsoft IIS超长畸形请求拒绝服务攻击" name_chs="Microsoft IIS超长畸形请求拒绝服务攻击" name_eng="Microsoft IIS Over-long Malformed Request Denial of Service" visible="true"/><rule ruleid="10113" enabled="true" group="337643547" action=" db  screen " name="利用Linksys Gozila.cgi脚本漏洞远程拒绝服务攻击" name_chs="利用Linksys Gozila.cgi脚本漏洞远程拒绝服务攻击" name_eng="Remote Denial of Service via Linksys Gozila.cgi Script Vulnerability" visible="true"/><rule ruleid="20517" enabled="true" group="69206191" action=" db  screen " name="Product Cart viewPrd.asp远程SQL注入攻击" name_chs="Product Cart viewPrd.asp远程SQL注入攻击" name_eng="Product Cart viewPrd.asp Remote SQL Injection" visible="true"/><rule ruleid="20516" enabled="true" group="136315051" action=" db  screen " name="利用Web Portal System wps_shop.cgi脚本漏洞远程执行命令" name_chs="利用Web Portal System wps_shop.cgi脚本漏洞远程执行命令" name_eng="Remote Command Execution via Web Portal System wps_shop.cgi Script Vulnerability" visible="true"/><rule ruleid="20689" enabled="true" group="203423915" action=" db  screen " name="eFiction上传图像文件执行命令攻击" name_chs="eFiction上传图像文件执行命令攻击" name_eng="eFiction Image File Upload Code Execution" visible="true"/><rule ruleid="20681" enabled="true" group="203423915" action=" db  screen " name="QnECMS adminfolderpath变量远程文件包含攻击" name_chs="QnECMS adminfolderpath变量远程文件包含攻击" name_eng="QnECMS adminfolderpath Variable Remote File Inclusion" visible="true"/><rule ruleid="20680" enabled="true" group="75497771" action=" db  screen " name="Ipswitch IMail SMTP Server畸形参数缓冲区溢出攻击" name_chs="Ipswitch IMail SMTP Server畸形参数缓冲区溢出攻击" name_eng="Ipswitch IMail SMTP Server Malformed Parameter Buffer Overflow" visible="true"/><rule ruleid="20683" enabled="true" group="69206315" action=" db  screen " name="HTTP协议请求超长Authorization选项远程缓冲区溢出攻击" name_chs="HTTP协议请求超长Authorization选项远程缓冲区溢出攻击" name_eng="HTTP Protocol Request Over-Long Authorization Option Remote Buffer Overflow" visible="true"/><rule ruleid="20682" enabled="true" group="203423915" action=" db  screen " name="Ultimate PHP Board _CONFIG[skin_dir]变量远程文件包含攻击" name_chs="Ultimate PHP Board _CONFIG[skin_dir]变量远程文件包含攻击" name_eng="Ultimate PHP Board _CONFIG[skin_dir] Variable Remote File Inclusion" visible="true"/><rule ruleid="20685" enabled="true" group="93323563" action=" db  screen " name="HP Node Manager SNMP服务远程缓冲区溢出攻击" name_chs="HP Node Manager SNMP服务远程缓冲区溢出攻击" name_eng="HP Node Manager SNMP Service Remote Buffer Overflow" visible="true"/><rule ruleid="20684" enabled="true" group="203423915" action=" db  screen " name="WordPress functions.php脚本远程文件包含攻击" name_chs="WordPress functions.php脚本远程文件包含攻击" name_eng="WordPress functions.php Script Remote File Inclusion" visible="true"/><rule ruleid="20687" enabled="true" group="203423915" action=" db  screen " name="phpBB viewtopic.php topic_id远程SQL注入攻击" name_chs="phpBB viewtopic.php topic_id远程SQL注入攻击" name_eng="phpBB viewtopic.php topic_id Remote SQL Injection" visible="true"/><rule ruleid="20686" enabled="true" group="93323563" action=" db  screen " name="NodeManager Professional SNMP Trap处理远程缓冲区溢出攻击" name_chs="NodeManager Professional SNMP Trap处理远程缓冲区溢出攻击" name_eng="NodeManager Professional SNMP Trap Handling Remote Buffer Overflow" visible="true"/><rule ruleid="40739" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware TIBS下载安装程序" name_chs="Windows系统下Adware TIBS下载安装程序" name_eng="Adware TIBS Downloading Installer on Windows" visible="true"/><rule ruleid="40738" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware ExactSearchBar下载安装程序" name_chs="Windows系统下Adware ExactSearchBar下载安装程序" name_eng="Adware ExactSearchBar Downloading Installer on Windows" visible="true"/><rule ruleid="40733" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware NewDotNet下载安装程序" name_chs="Windows系统下Adware NewDotNet下载安装程序" name_eng="Adware NewDotNet Downloading Installer on Windows" visible="true"/><rule ruleid="40732" enabled="true" group="224657482" action=" db  screen " name="BOT僵尸程序远程控制频道通信" name_chs="BOT僵尸程序远程控制频道通信" name_eng="BOT Zombies Remote Control of Communication" visible="true"/><rule ruleid="40731" enabled="true" group="99618891" action=" db  screen " name="Windows系统下黑客之门木马通信" name_chs="Windows系统下黑客之门木马通信" name_eng="Trojan Hacker's Door Communication on Windows" visible="true"/><rule ruleid="40730" enabled="true" group="69210191" action=" db  screen " name="Windows系统下sqlserver管理器ASP后门访问" name_chs="Windows系统下sqlserver管理器ASP后门访问" name_eng="sqlserver Manager ASP Backdoor on Windows" visible="true"/><rule ruleid="40737" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware ISTbar下载安装更新程序" name_chs="Windows系统下Adware ISTbar下载安装更新程序" name_eng="Adware ISTbar Downloading Installer on Windows" visible="true"/><rule ruleid="40736" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware FavoriteMan下载安装程序" name_chs="Windows系统下Adware FavoriteMan下载安装程序" name_eng="Adware FavoriteMan Downloading Installer on Windows" visible="true"/><rule ruleid="40735" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware ABetterInternet下载安装程序" name_chs="Windows系统下Adware ABetterInternet下载安装程序" name_eng="Adware ABetterInternet Downloading Installer on Windows" visible="true"/><rule ruleid="40734" enabled="true" group="99680329" action=" db  screen " name="Windows系统下Adware SecondThought下载安装程序" name_chs="Windows系统下Adware SecondThought下载安装程序" name_eng="Adware SecondThought Downloading Installer on Windows" visible="true"/><rule ruleid="20425" enabled="true" group="203423915" action=" db  screen " name="利用VBulletin index.php CGI脚本漏洞远程执行命令" name_chs="利用VBulletin index.php CGI脚本漏洞远程执行命令" name_eng="Remote Command Execution via VBulletin index.php CGI Script Vulnerability" visible="true"/><rule ruleid="20424" enabled="true" group="99615791" action=" db  screen  drop " name="Sasser（震荡波）蠕虫FTP后门缓冲区溢出攻击" name_chs="Sasser（震荡波）蠕虫FTP后门缓冲区溢出攻击" name_eng="Worm Sasser FTP Backdoor Buffer Overflow" visible="true"/><rule ruleid="20354" enabled="true" group="136315047" action=" db  screen " name="利用Logbook logbook.pl脚本漏洞远程执行命令" name_chs="利用Logbook logbook.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution Via Logbook logbook.pl Script Vulnerability" visible="true"/><rule ruleid="20352" enabled="true" group="210764331" action=" db  screen " name="IMAP服务暴力猜测口令攻击" name_chs="IMAP服务暴力猜测口令攻击" name_eng="IMAP Service Password Brute Force" visible="true"/><rule ruleid="20351" enabled="true" group="88080943" action=" db  screen " name="MS-SQL服务用户暴力猜解口令攻击" name_chs="MS-SQL服务用户暴力猜解口令攻击" name_eng="MS-SQL Service User Password Brute Force" visible="true"/><rule ruleid="20422" enabled="true" group="99615791" action=" db  screen  drop " name="Windows系统下Sasser（震荡波）蠕虫传播" name_chs="Windows系统下Sasser（震荡波）蠕虫传播" name_eng="Worm Sasser on Windows" visible="true"/><rule ruleid="20429" enabled="true" group="203423915" action=" db  screen " name="PHP Input/Ouput Wrapper远程包含函数执行命令攻击" name_chs="PHP Input/Ouput Wrapper远程包含函数执行命令攻击" name_eng="PHP Input/Ouput Wrapper Remote function Inclusion Command Execution" visible="true"/><rule ruleid="20359" enabled="true" group="69206315" action=" db  screen " name="Cisco ACS管理CGI程序远程缓冲区溢出攻击" name_chs="Cisco ACS管理CGI程序远程缓冲区溢出攻击" name_eng="Cisco ACS Management CGI Remote Buffer Overflow" visible="true"/><rule ruleid="20358" enabled="true" group="162529583" action=" db  screen  drop " name="Samba服务器call_trans2open远程缓冲区溢出攻击" name_chs="Samba服务器call_trans2open远程缓冲区溢出攻击" name_eng="Samba Server call_trans2open Remote Buffer Overflow" visible="true"/><rule ruleid="20195" enabled="true" group="68159511" action=" db  screen " name="John Roy Pi3Web tstisapi.dll远程拒绝服务攻击" name_chs="John Roy Pi3Web tstisapi.dll远程拒绝服务攻击" name_eng="John Roy Pi3Web tstisapi.dll Remote Denial of Service" visible="true"/><rule ruleid="20194" enabled="true" group="69206198" action=" db  screen " name="HIS Auktion脚本漏洞扫描利用" name_chs="HIS Auktion脚本漏洞扫描利用" name_eng="HIS Auktion Script Vulnerability Detection" visible="true"/><rule ruleid="20197" enabled="true" group="136315062" action=" db  screen " name="BizDB bizdb-search.cgi脚本漏洞扫描利用" name_chs="BizDB bizdb-search.cgi脚本漏洞扫描利用" name_eng="BizDB bizdb-search.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="20196" enabled="true" group="136315051" action=" db  screen " name="利用search.cgi脚本漏洞远程执行命令" name_chs="利用search.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via  search.cgi Script Vulnerability" visible="true"/><rule ruleid="20191" enabled="true" group="136315047" action=" db  screen " name="利用Virgil virgil.cgi脚本漏洞远程执行命令" name_chs="利用Virgil virgil.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via Virgil virgil.cgi Script Vulnerability" visible="true"/><rule ruleid="20190" enabled="true" group="136315051" action=" db  screen " name="利用vpopmail-CGIApps vadddomain脚本漏洞远程执行命令" name_chs="利用vpopmail-CGIApps vadddomain脚本漏洞远程执行命令" name_eng="Remote Code Execution via vpopmail-CGIApps vadddomain Script Vulnerability" visible="true"/><rule ruleid="20192" enabled="true" group="203423915" action=" db  screen " name="利用add-subject.php脚本漏洞非法上传文件" name_chs="利用add-subject.php脚本漏洞非法上传文件" name_eng="Illegal File Upload via add-subject.php Script Vulnerability" visible="true"/><rule ruleid="30118" enabled="true" group="69206202" action=" db  screen " name="Guestbook wguest.exe程序漏洞扫描探测" name_chs="Guestbook wguest.exe程序漏洞扫描探测" name_eng="Guestbook wguest.exe Vulnerability Detection" visible="true"/><rule ruleid="30119" enabled="true" group="69206202" action=" db  screen " name="利用Guestbook rguest.exe程序漏洞读取文件" name_chs="利用Guestbook rguest.exe程序漏洞读取文件" name_eng="File Reading via Guestbook rguest.exe Vulnerability" visible="true"/><rule ruleid="40029" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下TeleCommando木马建立连接" name_chs="Windows系统下TeleCommando木马建立连接" name_eng="Trojan TeleCommando Connection on Windows" visible="true"/><rule ruleid="20877" enabled="true" group="75497770" action=" db  screen " name="SoftiaCom WMailserver 1.0缓冲区溢出攻击" name_chs="SoftiaCom WMailserver 1.0缓冲区溢出攻击" name_eng="SoftiaCom WMailserver 1.0 Buffer Overflow" visible="true"/><rule ruleid="40027" enabled="true" group="99618891" action=" db  screen " name="Windows系统下TheThing木马连接通信" name_chs="Windows系统下TheThing木马连接通信" name_eng="Trojan TheThing Connection on Windows" visible="true"/><rule ruleid="30447" enabled="true" group="136323130" action=" db  screen " name="shop.pl脚本漏洞扫描探测" name_chs="shop.pl脚本漏洞扫描探测" name_eng="shop.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30113" enabled="true" group="136315066" action=" db  screen " name="arpanet perlshop.cgi脚本漏洞扫描探测" name_chs="arpanet perlshop.cgi脚本漏洞扫描探测" name_eng="arpanet perlshop.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30442" enabled="true" group="203431994" action=" db  screen " name="PHP-Nuke opendir.php脚本漏洞扫描探测" name_chs="PHP-Nuke opendir.php脚本漏洞扫描探测" name_eng="PHP-Nuke opendir.php Script Vulnerability Detection" visible="true"/><rule ruleid="30115" enabled="true" group="136315062" action=" db  screen  drop " name="PHP/FI php.cgi脚本漏洞扫描探测" name_chs="PHP/FI php.cgi脚本漏洞扫描探测" name_eng="PHP/FI php.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30440" enabled="true" group="136323130" action=" db  screen " name="VPOPMail vpopmail.php脚本漏洞扫描探测" name_chs="VPOPMail vpopmail.php脚本漏洞扫描探测" name_eng="VPOPMail vpopmail.php Script Vulnerability Detection" visible="true"/><rule ruleid="30117" enabled="true" group="69206202" action=" db  screen " name="Guestbook rguest.exe程序漏洞扫描探测" name_chs="Guestbook rguest.exe程序漏洞扫描探测" name_eng="Guestbook rguest.exe Vulnerability Detection" visible="true"/><rule ruleid="40355" enabled="true" group="68157646" action=" db  screen " name="Frontpage fpadmin.htm文件扫描探测" name_chs="Frontpage fpadmin.htm文件扫描探测" name_eng="Frontpage fpadmin.htm File Detection" visible="true"/><rule ruleid="40606" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Windows Mite木马通信" name_chs="Windows系统下Windows Mite木马通信" name_eng="Trojan Windows Mite Communication on Windows" visible="true"/><rule ruleid="40605" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下WebServect木马通信" name_chs="Windows系统下WebServect木马通信" name_eng="Trojan WebServect Communication on Windows" visible="true"/><rule ruleid="20875" enabled="true" group="99615018" action=" db  screen " name="CA BrightStor Agent for Microsoft SQL缓冲区溢出攻击" name_chs="CA BrightStor Agent for Microsoft SQL缓冲区溢出攻击" name_eng="CA BrightStor Agent for Microsoft SQL Buffer Overflow" visible="true"/><rule ruleid="40603" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下WanRemote木马通信" name_chs="Windows系统下WanRemote木马通信" name_eng="Trojan WanRemote Communication on Windows" visible="true"/><rule ruleid="40602" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Voodoo Doll木马通信" name_chs="Windows系统下Voodoo Doll木马通信" name_eng="Trojan Voodoo Doll Communication on Windows" visible="true"/><rule ruleid="40353" enabled="true" group="68157646" action=" db  screen " name="Frontpage fpremadm.exe文件扫描探测" name_chs="Frontpage fpremadm.exe文件扫描探测" name_eng="Frontpage fpremadm.exe File Detection" visible="true"/><rule ruleid="40352" enabled="true" group="68157646" action=" db  screen " name="Frontpage fpadmcgi.exe文件扫描探测" name_chs="Frontpage fpadmcgi.exe文件扫描探测" name_eng="Frontpage fpadmcgi.exe File Detection" visible="true"/><rule ruleid="20872" enabled="true" group="68157738" action=" db  screen " name="IASystemInfo.DLL ActiveX控件远程栈溢出攻击" name_chs="IASystemInfo.DLL ActiveX控件远程栈溢出攻击" name_eng="IASystemInfo.DLL ActiveX Control Remote Stack Overflow" visible="true"/><rule ruleid="40359" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下WinCrash 2.0木马建立连接" name_chs="Windows系统下WinCrash 2.0木马建立连接" name_eng="Trojan WinCrash 2.0 Connection on Windows" visible="true"/><rule ruleid="40358" enabled="true" group="69206223" action=" db  screen " name="通过Web服务执行.bat程序" name_chs="通过Web服务执行.bat程序" name_eng=".bat Program Execution via Web Service" visible="true"/><rule ruleid="40609" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Xanadu 1.1木马通信" name_chs="Windows系统下Xanadu 1.1木马通信" name_eng="Trojan Xanadu 1.1 Communication on Windows" visible="true"/><rule ruleid="20873" enabled="true" group="68157738" action=" db  screen " name="Nullsoft Winamp畸形播放列表文件处理远程缓冲区溢出攻击" name_chs="Nullsoft Winamp畸形播放列表文件处理远程缓冲区溢出攻击" name_eng="Nullsoft Winamp Malformed Playlist File Processing Remote Buffer Overflow" visible="true"/><rule ruleid="20870" enabled="true" group="70254890" action=" db  screen " name="FTP服务器LIST命令超长参数远程缓冲区溢出攻击" name_chs="FTP服务器LIST命令超长参数远程缓冲区溢出攻击" name_eng="FTP Server LIST Command Over-Long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20871" enabled="true" group="68157738" action=" db  screen " name="Symantec Norton个人防火墙ActiveX控件远程溢出攻击" name_chs="Symantec Norton个人防火墙ActiveX控件远程溢出攻击" name_eng="Symantec Norton Private Firewall ActiveX Control Remote Buffer Overflow" visible="true"/><rule ruleid="20223" enabled="true" group="203423914" action=" db  screen " name="利用WebPALS pals-cgi程序漏洞远程执行命令" name_chs="利用WebPALS pals-cgi程序漏洞远程执行命令" name_eng="Remote Code Execution via WebPALS pals-cgi Vulnerability" visible="true"/><rule ruleid="20222" enabled="true" group="69214262" action=" db  screen " name="NAI PGP Keyserver cs.exe脚本漏洞扫描利用" name_chs="NAI PGP Keyserver cs.exe脚本漏洞扫描利用" name_eng="NAI PGP Keyserver cs.exe Script Vulnerability Detection" visible="true"/><rule ruleid="20221" enabled="true" group="69214262" action=" db  screen " name="NAI PGP Keyserver console.exe脚本漏洞扫描利用" name_chs="NAI PGP Keyserver console.exe脚本漏洞扫描利用" name_eng="NAI PGP Keyserver console.exe Script Vulnerability Detection" visible="true"/><rule ruleid="40023" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下DeepThroat木马通信" name_chs="Windows系统下DeepThroat木马通信" name_eng="Trojan DeepThroat Communication on Windows" visible="true"/><rule ruleid="20227" enabled="true" group="69214266" action=" db  screen " name="Trend Micro OfficeScan jdkRqNotify.exe脚本漏洞扫描探测" name_chs="Trend Micro OfficeScan jdkRqNotify.exe脚本漏洞扫描探测" name_eng="Trend Micro OfficeScan jdkRqNotify.exe Script Vulnerability Detection" visible="true"/><rule ruleid="20226" enabled="true" group="136315062" action=" db  screen " name="JJ CGI例子程序漏洞扫描利用" name_chs="JJ CGI例子程序漏洞扫描利用" name_eng="JJ CGI Sample Vulnerability Detection" visible="true"/><rule ruleid="20225" enabled="true" group="203423926" action=" db  screen " name="DCForum dcboard.cgi脚本漏洞扫描利用" name_chs="DCForum dcboard.cgi脚本漏洞扫描利用" name_eng="DCForum dcboard.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="20224" enabled="true" group="203431978" action=" db  screen " name="WebPALS pals-cgi CGI程序漏洞扫描探测" name_chs="WebPALS pals-cgi CGI程序漏洞扫描探测" name_eng="WebPALS pals-cgi CGI Vulnerability Detection" visible="true"/><rule ruleid="20229" enabled="true" group="136315066" action=" db  screen " name="Informix Webdriver CGI程序漏洞扫描探测" name_chs="Informix Webdriver CGI程序漏洞扫描探测" name_eng="Informix Webdriver CGI Vulnerability Detection" visible="true"/><rule ruleid="30204" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.bootparamd服务存在性TCP扫描探测" name_chs="Solaris rpc.bootparamd服务存在性TCP扫描探测" name_eng="Solaris rpc.bootparamd Service TCP Detection" visible="true"/><rule ruleid="30205" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.rusersd服务存在性UDP扫描探测" name_chs="Solaris rpc.rusersd服务存在性UDP扫描探测" name_eng="Solaris rpc.rusersd Service UDP Detection" visible="true"/><rule ruleid="40289" enabled="true" group="69206206" action=" db  screen " name="利用Microsoft IIS .htr文件名截断漏洞获取脚本源码攻击" name_chs="利用Microsoft IIS .htr文件名截断漏洞获取脚本源码攻击" name_eng="Script Source Code Disclosure via Microsoft IIS .htr Filename Truncation Vulnerability" visible="true"/><rule ruleid="30207" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.admind服务存在性TCP扫描探测" name_chs="Solaris rpc.admind服务存在性TCP扫描探测" name_eng="Solaris rpc.admind Service TCP Detection" visible="true"/><rule ruleid="30200" enabled="true" group="136315062" action=" db  screen " name="利用Verity's Search`97 search97.vts脚本漏洞远程遍历目录" name_chs="利用Verity's Search`97 search97.vts脚本漏洞远程遍历目录" name_eng="Remote Directory Traversal via Verity's Search`97 search97.vts Script Vulnerability" visible="true"/><rule ruleid="30201" enabled="true" group="151003190" action=" db  screen " name="Solaris rpc.ypupdated服务存在性TCP扫描探测" name_chs="Solaris rpc.ypupdated服务存在性TCP扫描探测" name_eng="Solaris rpc.ypupdated Service TCP Detection" visible="true"/><rule ruleid="30202" enabled="true" group="151003194" action=" db  screen " name="Linux rpc.mountd服务存在性UDP扫描探测" name_chs="Linux rpc.mountd服务存在性UDP扫描探测" name_eng="Linux rpc.mountd Service UDP Detection" visible="true"/><rule ruleid="30203" enabled="true" group="151003194" action=" db  screen " name="Linux rpc.mountd服务存在性TCP扫描探测" name_chs="Linux rpc.mountd服务存在性TCP扫描探测" name_eng="Linux rpc.mountd Service TCP Detection" visible="true"/><rule ruleid="40283" enabled="true" group="69206201" action=" db  screen " name="Microsoft IIS 4.0 srch.htm文件扫描探测" name_chs="Microsoft IIS 4.0 srch.htm文件扫描探测" name_eng="Microsoft IIS 4.0 srch.htm File Detection" visible="true"/><rule ruleid="30208" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.rstatd服务存在性TCP扫描探测" name_chs="Solaris rpc.rstatd服务存在性TCP扫描探测" name_eng="Solaris rpc.rstatd Service TCP Detection" visible="true"/><rule ruleid="30209" enabled="true" group="151003194" action=" db  screen " name="Solaris rpc.rexd服务存在性TCP扫描探测" name_chs="Solaris rpc.rexd服务存在性TCP扫描探测" name_eng="Solaris rpc.rexd Service TCP Detection" visible="true"/><rule ruleid="30542" enabled="true" group="136315066" action=" db  screen " name="W-Agora site参数远程目录遍历攻击" name_chs="W-Agora site参数远程目录遍历攻击" name_eng="W-Agora site Parameter Remote Directory Traversal" visible="true"/><rule ruleid="40513" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Ghost木马通信" name_chs="Windows系统下Ghost木马通信" name_eng="Trojan Ghost Communication on Windows" visible="true"/><rule ruleid="40512" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Frenzy木马连接建立" name_chs="Windows系统下Frenzy木马连接建立" name_eng="Trojan Frenzy Trojan Connection on Windows" visible="true"/><rule ruleid="40511" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Frenzy木马通信" name_chs="Windows系统下Frenzy木马通信" name_eng="Trojan Frenzy Communication on Windows" visible="true"/><rule ruleid="40510" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Forced Entry木马通信" name_chs="Windows系统下Forced Entry木马通信" name_eng="Trojan Forced Entry Communication on Windows" visible="true"/><rule ruleid="40517" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Hell-Driver木马通信" name_chs="Windows系统下Hell-Driver木马通信" name_eng="Trojan Hell-Driver Communication on Windows" visible="true"/><rule ruleid="40516" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Hackers World木马通信" name_chs="Windows系统下Hackers World木马通信" name_eng="Trojan Hackers World Communication on Windows" visible="true"/><rule ruleid="40515" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下G-Spot木马通信" name_chs="Windows系统下G-Spot木马通信" name_eng="Trojan G-Spot Communication on Windows" visible="true"/><rule ruleid="40514" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Gift木马通信" name_chs="Windows系统下Gift木马通信" name_eng="Trojan Gift Communication on Windows" visible="true"/><rule ruleid="40519" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Host Control木马通信" name_chs="Windows系统下Host Control木马通信" name_eng="Trojan Host Control Communication on Windows" visible="true"/><rule ruleid="40518" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Hellz Addiction木马通信" name_chs="Windows系统下Hellz Addiction木马通信" name_eng="Trojan Hellz Addiction Communication on Windows" visible="true"/><rule ruleid="40021" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Gatecrasher木马建立连接" name_chs="Windows系统下Gatecrasher木马建立连接" name_eng="Trojan Gatecrasher Connection on Windows" visible="true"/><rule ruleid="30061" enabled="true" group="211820601" action=" db  screen " name="DNS服务获取服务器版本号请求操作" name_chs="DNS服务获取服务器版本号请求操作" name_eng="DNS Service Server Version Number Request" visible="true"/><rule ruleid="30064" enabled="true" group="204480569" action=" db  screen " name="漏洞扫描器ISS扫描FTP服务尝试登录" name_chs="漏洞扫描器ISS扫描FTP服务尝试登录" name_eng="ISS Scanner Scanning FTP Service Login Attempt" visible="true"/><rule ruleid="30066" enabled="true" group="204480570" action=" db  screen " name="漏洞扫描器Saint扫描FTP服务" name_chs="漏洞扫描器Saint扫描FTP服务" name_eng="Saint Scanner Scanning FTP Service" visible="true"/><rule ruleid="30067" enabled="true" group="204480570" action=" db  screen " name="漏洞扫描器SATAN扫描FTP服务" name_chs="漏洞扫描器SATAN扫描FTP服务" name_eng="SATAN Scanner Scanning FTP Service" visible="true"/><rule ruleid="50130" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具POCO用户登录" name_chs="P2P文件共享工具POCO用户登录" name_eng="P2P File Sharing Tool POCO User Login" visible="true"/><rule ruleid="50131" enabled="true" group="233963613" action=" db  screen " name="在线播放WMV流媒体内容" name_chs="在线播放WMV流媒体内容" name_eng="WMV Stream Media Content Online Playing" visible="true"/><rule ruleid="50132" enabled="true" group="233963613" action=" db  screen " name="在线播放RM流媒体内容" name_chs="在线播放RM流媒体内容" name_eng="RM Stream Media Content Online Playing" visible="true"/><rule ruleid="50133" enabled="true" group="233963613" action=" db  screen " name="P2P语音聊天工具Skype操作" name_chs="P2P语音聊天工具Skype操作" name_eng="P2P Voice Chat Tool Skype" visible="true"/><rule ruleid="50134" enabled="true" group="99745885" action=" db  screen " name="网络游戏魔兽世界（World of Warcraft）网络对战" name_chs="网络游戏魔兽世界（World of Warcraft）网络对战" name_eng="Online Game World of Warcraft User Login" visible="true"/><rule ruleid="50136" enabled="true" group="233963613" action=" db  screen " name="即时通信软件Jabber用户登录" name_chs="即时通信软件Jabber用户登录" name_eng="Instant Messaging Software Jabber User Login" visible="true"/><rule ruleid="50137" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具Kamun用户登录" name_chs="P2P文件共享工具Kamun用户登录" name_eng="P2P File Sharing Tool Kamun User Login" visible="true"/><rule ruleid="50138" enabled="true" group="99745885" action=" db  screen " name="P2P文件共享工具OPENEXT用户登录" name_chs="P2P文件共享工具OPENEXT用户登录" name_eng="P2P File Sharing Tool OPENEXT User Login" visible="true"/><rule ruleid="50139" enabled="true" group="99745885" action=" db  screen  drop " name="网络游戏江湖用户登录" name_chs="网络游戏江湖用户登录" name_eng="Online Game Jianghu User Login" visible="true"/><rule ruleid="30133" enabled="true" group="151003198" action=" db  screen " name="Solaris rpc.sadmind服务存在性UDP扫描探测" name_chs="Solaris rpc.sadmind服务存在性UDP扫描探测" name_eng="Solaris rpc.sadmind Service UDP Detection" visible="true"/><rule ruleid="20248" enabled="true" group="143655211" action=" db  screen " name="Wu-imapd部分Mailbox属性远程缓冲区溢出攻击" name_chs="Wu-imapd部分Mailbox属性远程缓冲区溢出攻击" name_eng="Wu-imapd Partial Mailbox Attribute Remote Buffer Overflow" visible="true"/><rule ruleid="40805" enabled="true" group="68223050" action=" db  screen " name="Microsoft Windows矢量标记语言缓冲区溢出攻击" name_chs="Microsoft Windows矢量标记语言缓冲区溢出攻击" name_eng="Microsoft Windows Vector Markup Language Buffer Overflow" visible="true"/><rule ruleid="40375" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Shaft分布端和主控端通信" name_chs="DDOS工具Shaft分布端和主控端通信" name_eng="Communication Between DDOS Shaft Distributed End and Console" visible="true"/><rule ruleid="40374" enabled="true" group="166727755" action=" db  screen " name="DDOS工具Shaft主控端和分布端通信" name_chs="DDOS工具Shaft主控端和分布端通信" name_eng="Communication Between DDOS Shaft Console and Distributed End" visible="true"/><rule ruleid="40379" enabled="true" group="166727759" action=" db  screen " name="DDOS工具TFN主控端向分布端发送指令" name_chs="DDOS工具TFN主控端向分布端发送指令" name_eng="DDOS Tool TFN Console Sending Command to Distributed End" visible="true"/><rule ruleid="40378" enabled="true" group="166727759" action=" db  screen " name="DDOS工具TFN服务器端回应" name_chs="DDOS工具TFN服务器端回应" name_eng="DDOS TFN Server Response" visible="true"/><rule ruleid="40044" enabled="true" group="204537949" action=" db  screen " name="FTP服务anonymous匿名用户认证" name_chs="FTP服务anonymous匿名用户认证" name_eng="FTP Service Anonymous User Authentication" visible="true" merge="[t7200,si,di]"/><rule ruleid="20347" enabled="true" group="204472878" action=" db  screen " name="FTP服务暴力猜测用户口令" name_chs="FTP服务暴力猜测用户口令" name_eng="FTP Service User Password Brute Force" visible="true"/><rule ruleid="10065" enabled="true" group="73402399" action=" db  screen " name="Windows 9x SMB_COM_SEND_SINGLE_BLOCK操作拒绝服务攻击" name_chs="Windows 9x SMB_COM_SEND_SINGLE_BLOCK操作拒绝服务攻击" name_eng="Windows 9x SMB_COM_SEND_SINGLE_BLOCK Denial of Service" visible="true"/><rule ruleid="20175" enabled="true" group="203431994" action=" db  screen " name="phpGB savesettings.php脚本漏洞扫描探测" name_chs="phpGB savesettings.php脚本漏洞扫描探测" name_eng="phpGB savesettings.php Script Vulnerability Detection" visible="true"/><rule ruleid="20174" enabled="true" group="136323130" action=" db  screen " name="wordtrans-web wordtrans.php脚本漏洞扫描探测" name_chs="wordtrans-web wordtrans.php脚本漏洞扫描探测" name_eng="wordtrans-web wordtrans.php Script Vulnerability Detection" visible="true"/><rule ruleid="10059" enabled="true" group="203423898" action=" db  screen " name="Netscape Enterprise Server Web Publisher拒绝服务攻击" name_chs="Netscape Enterprise Server Web Publisher拒绝服务攻击" name_eng="Netscape Enterprise Server Web Publisher Denial of Service" visible="true"/><rule ruleid="10058" enabled="true" group="233834526" action=" db  screen " name="ICMP-Flood淹没拒绝服务攻击" name_chs="ICMP-Flood淹没拒绝服务攻击" name_eng="ICMP-Flood Denial of Service Attacks" visible="true" merge="[t3600,di]"/><rule ruleid="10056" enabled="true" group="233834526" action=" db  screen " name="SYN-Flood半开TCP连接淹没拒绝服务攻击" name_chs="SYN-Flood半开TCP连接淹没拒绝服务攻击" name_eng="SYN-Flood Half-open TCP Connection Denial of Service Attack" visible="true" merge="[t1800,di]"/><rule ruleid="10055" enabled="true" group="233840694" action=" db  screen " name="漏洞扫描器Cybercop Scanner模拟UDP BOMB攻击" name_chs="漏洞扫描器Cybercop Scanner模拟UDP BOMB攻击" name_eng="Cybercop Scanner UDP BOMB Simulation" visible="true"/><rule ruleid="10052" enabled="true" group="88082463" action=" db  screen " name="Microsoft SQL Server 2000 Resolution服务keep-alive拒绝服务攻击" name_chs="Microsoft SQL Server 2000 Resolution服务keep-alive拒绝服务攻击" name_eng="Microsoft SQL Server 2000 Resolution Service keep-alive Denial of Service" visible="true"/><rule ruleid="10051" enabled="true" group="88082463" action=" db  screen " name="Microsoft SQL Server 2000 Resolution服务远程堆破坏拒绝服务攻击" name_chs="Microsoft SQL Server 2000 Resolution服务远程堆破坏拒绝服务攻击" name_eng="Microsoft SQL Server 2000 Resolution Service Remote Heap Corruption Denial of Service" visible="true"/><rule ruleid="10050" enabled="true" group="69206174" action=" db  screen " name="ExAir示例脚本search.asp拒绝服务攻击" name_chs="ExAir示例脚本search.asp拒绝服务攻击" name_eng="ExAir Sample Script search.asp Denial of Service" visible="true"/><rule ruleid="40041" enabled="true" group="204537946" action=" db  screen " name="FTP服务客户端使用空口令登录" name_chs="FTP服务客户端使用空口令登录" name_eng="Null Password for FTP Service Client" visible="true"/><rule ruleid="20768" enabled="true" group="203423914" action=" db  screen " name="Claroline E-Learning应用多个远程SQL注入攻击" name_chs="Claroline E-Learning应用多个远程SQL注入攻击" name_eng="Claroline E-Learning Application multiple Remote SQL Injections" visible="true"/><rule ruleid="20769" enabled="true" group="136315051" action=" db  screen " name="Pico Server远程命令注入攻击" name_chs="Pico Server远程命令注入攻击" name_eng="Pico Server Remote Command Injection" visible="true"/><rule ruleid="20766" enabled="true" group="136315051" action=" db  screen " name="Neteyes NexusWay Border Gateway远程命令执行攻击" name_chs="Neteyes NexusWay Border Gateway远程命令执行攻击" name_eng="Neteyes NexusWay Border Gateway Remote Code Execution" visible="true"/><rule ruleid="20767" enabled="true" group="203423915" action=" db  screen " name="MidiCart ASP searchstring参数远程SQL注入攻击" name_chs="MidiCart ASP searchstring参数远程SQL注入攻击" name_eng="MidiCart ASP searchstring Parameter Remote SQL Injection" visible="true"/><rule ruleid="20764" enabled="true" group="203423914" action=" db  screen " name="Contrexx pid变量远程SQL注入攻击" name_chs="Contrexx pid变量远程SQL注入攻击" name_eng="Contrexx pid Variable Remote SQL Injection" visible="true"/><rule ruleid="20765" enabled="true" group="166725675" action=" db  screen " name="Peercast URL格式串处理攻击" name_chs="Peercast URL格式串处理攻击" name_eng="Peercast URL String Handling Vulnerability" visible="true"/><rule ruleid="20762" enabled="true" group="203423914" action=" db  screen " name="RunCMS newtopic.php远程SQL注入攻击" name_chs="RunCMS newtopic.php远程SQL注入攻击" name_eng="RunCMS newtopic.php Remote SQL Injection" visible="true"/><rule ruleid="20763" enabled="true" group="203423914" action=" db  screen " name="MyBB search.php脚本远程SQL注入攻击" name_chs="MyBB search.php脚本远程SQL注入攻击" name_eng="MyBB search.php Script Remote SQL Injection" visible="true"/><rule ruleid="20760" enabled="true" group="136315050" action=" db  screen " name="man2web CGI脚本远程命令执行攻击" name_chs="man2web CGI脚本远程命令执行攻击" name_eng="man2web CGI Script Remote Code Execution" visible="true"/><rule ruleid="20761" enabled="true" group="203423914" action=" db  screen " name="phpLDAPadmin welcome.php远程命令执行攻击" name_chs="phpLDAPadmin welcome.php远程命令执行攻击" name_eng="phpLDAPadmin welcome.php Remote Code Execution" visible="true"/><rule ruleid="10129" enabled="true" group="99616799" action=" db  screen  drop " name="Microsoft Windows TCP/IP协议栈畸形IP头选项拒绝服务攻击" name_chs="Microsoft Windows TCP/IP协议栈畸形IP头选项拒绝服务攻击" name_eng="Microsoft Windows TCP/IP Protocol Stack Malformed IP Header Option Denial of Service" visible="true"/><rule ruleid="10128" enabled="true" group="137365531" action=" db  screen " name="Wu-ftpd多文件名扩展请求远程拒绝服务攻击" name_chs="Wu-ftpd多文件名扩展请求远程拒绝服务攻击" name_eng="Wu-ftpd multiple Filename Requests Remote Denial of Service" visible="true"/><rule ruleid="10123" enabled="true" group="166725659" action=" db  screen " name="IDENT服务淹没拒绝服务攻击" name_chs="IDENT服务淹没拒绝服务攻击" name_eng="IDENT Service Flood Denial of Service" visible="true"/><rule ruleid="10122" enabled="true" group="233834527" action=" db  screen " name="Windows NT/9x畸形TCP/IP包淹没拒绝服务攻击" name_chs="Windows NT/9x畸形TCP/IP包淹没拒绝服务攻击" name_eng="Windows NT/9x Malformed TCP/IP Packet Flood Denial of Service" visible="true"/><rule ruleid="10121" enabled="true" group="233834523" action=" db  screen " name="Windows 2000 IKE拒绝服务攻击" name_chs="Windows 2000 IKE拒绝服务攻击" name_eng="Windows 2000 IKE Denial of Service" visible="true"/><rule ruleid="20501" enabled="true" group="203423919" action=" db  screen " name="PostNuke pnModFunc函数本地文件包含攻击" name_chs="PostNuke pnModFunc函数本地文件包含攻击" name_eng="PostNuke pnModFunc function Local File Inclusion" visible="true"/><rule ruleid="10127" enabled="true" group="99616795" action=" db  screen " name="Microsoft NT RAS/PPTP畸形控制包远程拒绝服务攻击" name_chs="Microsoft NT RAS/PPTP畸形控制包远程拒绝服务攻击" name_eng="Microsoft NT RAS/PPTP Malformed Packet Remote Denial of Service" visible="true"/><rule ruleid="10126" enabled="true" group="211814430" action=" db  screen " name="DNS服务连接请求淹没拒绝服务攻击" name_chs="DNS服务连接请求淹没拒绝服务攻击" name_eng="DNS Service Connection Request Flood Denial of Service" visible="true"/><rule ruleid="10125" enabled="true" group="89131031" action=" db  screen " name="Windows 2000/NT打印服务拒绝服务攻击" name_chs="Windows 2000/NT打印服务拒绝服务攻击" name_eng="Windows 2000/NT Spooler Denial of Service" visible="true"/><rule ruleid="10124" enabled="true" group="166725659" action=" db  screen " name="Microsoft Windows NT 4.0远程注册表操作拒绝服务攻击" name_chs="Microsoft Windows NT 4.0远程注册表操作拒绝服务攻击" name_eng="Microsoft Windows NT 4.0 Remote Registry Operation Denial of Service" visible="true"/><rule ruleid="20698" enabled="true" group="69206186" action=" db  screen " name="ASPNuke article.asp articleid变量远程SQL注入攻击" name_chs="ASPNuke article.asp articleid变量远程SQL注入攻击" name_eng="ASPNuke article.asp articleid Variable Remote SQL Injection" visible="true"/><rule ruleid="20699" enabled="true" group="203423914" action=" db  screen " name="Comet WebFileManager CheckUpload.php远程文件包含攻击" name_chs="Comet WebFileManager CheckUpload.php远程文件包含攻击" name_eng="Comet WebFileManager CheckUpload.php Remote File Inclusion" visible="true"/><rule ruleid="20692" enabled="true" group="203423914" action=" db  screen " name="phpBB Hacks List模块hack_id远程SQL注入攻击" name_chs="phpBB Hacks List模块hack_id远程SQL注入攻击" name_eng="phpBB Hacks List Module hack_id Remote SQL Injection" visible="true"/><rule ruleid="20693" enabled="true" group="203423915" action=" db  screen " name="ACal Calendar day.php远程文件包含攻击" name_chs="ACal Calendar day.php远程文件包含攻击" name_eng="ACal Calendar day.php Remote File Inclusion" visible="true"/><rule ruleid="20690" enabled="true" group="203423914" action=" db  screen " name="Complete PHP Counter list.php远程SQL注入攻击" name_chs="Complete PHP Counter list.php远程SQL注入攻击" name_eng="Complete PHP Counter list.php Remote SQL Injection" visible="true"/><rule ruleid="20691" enabled="true" group="69206186" action=" db  screen " name="SimpleBlog edit.asp远程SQL注入攻击" name_chs="SimpleBlog edit.asp远程SQL注入攻击" name_eng="SimpleBlog edit.asp Remote SQL Injection" visible="true"/><rule ruleid="20696" enabled="true" group="69206186" action=" db  screen " name="Zixforum layid变量远程SQL注入攻击" name_chs="Zixforum layid变量远程SQL注入攻击" name_eng="Zixforum layid Variable Remote SQL Injection" visible="true"/><rule ruleid="20697" enabled="true" group="203423914" action=" db  screen " name="Arki-DB catid变量远程SQL注入攻击" name_chs="Arki-DB catid变量远程SQL注入攻击" name_eng="Arki-DB catid Variable Remote SQL Injection" visible="true"/><rule ruleid="20694" enabled="true" group="203423915" action=" db  screen " name="ActionApps GLOBALS[AA_INC_PATH]变量远程文件包含攻击" name_chs="ActionApps GLOBALS[AA_INC_PATH]变量远程文件包含攻击" name_eng="ActionApps GLOBALS[AA_INC_PATH] Variable Remote File Inclusion" visible="true"/><rule ruleid="20695" enabled="true" group="203423915" action=" db  screen " name="Albinator Config_rootdir变量远程文件包含攻击" name_chs="Albinator Config_rootdir变量远程文件包含攻击" name_eng="Albinator Config_rootdir Variable Remote File Inclusion" visible="true"/><rule ruleid="30266" enabled="true" group="203431994" action=" db  screen " name="Achievo class.atkdateattribute.js.php脚本漏洞扫描探测" name_chs="Achievo class.atkdateattribute.js.php脚本漏洞扫描探测" name_eng="Achievo class.atkdateattribute.js.php Script Vulnerability Detection" visible="true"/><rule ruleid="30267" enabled="true" group="203431994" action=" db  screen " name="Mantis summary_graph_functions.php脚本漏洞扫描探测" name_chs="Mantis summary_graph_functions.php脚本漏洞扫描探测" name_eng="Mantis summary_graph_functions.php Script Vulnerability Detection" visible="true"/><rule ruleid="40757" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Pcshare2005木马通信" name_chs="Windows系统下Pcshare2005木马通信" name_eng="Trojan Pcshare2005 Communication on Windows" visible="true"/><rule ruleid="30265" enabled="true" group="68157626" action=" db  screen " name="获取Apache 2.0 for Windows绝对安装路径攻击" name_chs="获取Apache 2.0 for Windows绝对安装路径攻击" name_eng="Apache 2.0 for Windows Absolute Installation Path Disclosure" visible="true"/><rule ruleid="20436" enabled="true" group="203423919" action=" db  screen " name="Print Topic Mod printview.php SQL注入攻击" name_chs="Print Topic Mod printview.php SQL注入攻击" name_eng="Print Topic Mod printview.php SQL Injection" visible="true"/><rule ruleid="20437" enabled="true" group="203423919" action=" db  screen " name="AntiBoard antiboard.php SQL注入攻击" name_chs="AntiBoard antiboard.php SQL注入攻击" name_eng="AntiBoard antiboard.php SQL Injection" visible="true"/><rule ruleid="20434" enabled="true" group="136315055" action=" db  screen " name="利用Extropia WebStore web_store.cgi脚本漏洞远程执行命令" name_chs="利用Extropia WebStore web_store.cgi脚本漏洞远程执行命令" name_eng="Remote Command Execution via Extropia WebStore web_store.cgi Script Vulnerability" visible="true"/><rule ruleid="20435" enabled="true" group="136315055" action=" db  screen " name="PHP-Nuke Search功能SQL注入攻击" name_chs="PHP-Nuke Search功能SQL注入攻击" name_eng="PHP-Nuke Search function SQL Injection" visible="true"/><rule ruleid="20432" enabled="true" group="222300207" action=" db  screen  drop " name="MySQL空口令HASH绕过认证攻击" name_chs="MySQL空口令HASH绕过认证攻击" name_eng="MySQL Null Password HASH Authentication Bypass" visible="true"/><rule ruleid="20433" enabled="true" group="203423919" action=" db  screen " name="phpBB viewtopic.php CGI脚本SQL注入攻击" name_chs="phpBB viewtopic.php CGI脚本SQL注入攻击" name_eng="phpBB viewtopic.php CGI Script SQL Injection" visible="true"/><rule ruleid="20430" enabled="true" group="203423919" action=" db  screen " name="phpMyAdmin远程PHP代码注入攻击" name_chs="phpMyAdmin远程PHP代码注入攻击" name_eng="phpMyAdmin Remote PHP Code Injection" visible="true"/><rule ruleid="20431" enabled="true" group="203423915" action=" db  screen " name="利用Pivot module_db.php脚本漏洞远程执行命令" name_chs="利用Pivot module_db.php脚本漏洞远程执行命令" name_eng="Remote Command Execution via Pivot module_db.php Script Vulnerability" visible="true"/><rule ruleid="20438" enabled="true" group="137365547" action=" db  screen " name="OpenFTPD SITE MSG命令远程格式串漏洞攻击" name_chs="OpenFTPD SITE MSG命令远程格式串漏洞攻击" name_eng="OpenFTPD SITE MSG Command Remote Format String Vulnerability" visible="true"/><rule ruleid="20439" enabled="true" group="83887151" action=" db  screen " name="Windows系统下MSBLAST（冲击波）蠕虫及其变种传播" name_chs="Windows系统下MSBLAST（冲击波）蠕虫及其变种传播" name_eng="Worm MSBLAST and Variants on Windows" visible="true"/><rule ruleid="20186" enabled="true" group="136315047" action=" db  screen  drop " name="利用CSVForm csvform.pl脚本漏洞远程执行命令" name_chs="利用CSVForm csvform.pl脚本漏洞远程执行命令" name_eng="Remote Code Execution via CSVForm csvform.pl Script Vulnerability" visible="true"/><rule ruleid="20187" enabled="true" group="69206191" action=" db  screen " name="利用Apache Win32批处理脚本漏洞远程执行命令" name_chs="利用Apache Win32批处理脚本漏洞远程执行命令" name_eng="Remote Code Execution via Apache Win32 Batch Script Vulnerability" visible="true"/><rule ruleid="20184" enabled="true" group="136315047" action=" db  screen " name="Abe Timmerman zml.cgi脚本漏洞扫描探测" name_chs="Abe Timmerman zml.cgi脚本漏洞扫描探测" name_eng="Abe Timmerman zml.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="20185" enabled="true" group="136315051" action=" db  screen  drop " name="利用IRIX webdist.cgi脚本漏洞远程执行命令" name_chs="利用IRIX webdist.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via IRIX webdist.cgi Script Vulnerability" visible="true"/><rule ruleid="20182" enabled="true" group="203423915" action=" db  screen " name="利用Achievo class.atkdateattribute.js.php脚本漏洞执行命令" name_chs="利用Achievo class.atkdateattribute.js.php脚本漏洞执行命令" name_eng="Code Execution via Achievo class.atkdateattribute.js.php Script Vulnerability" visible="true"/><rule ruleid="20183" enabled="true" group="203423915" action=" db  screen " name="利用Mantis summary_graph_functions.php脚本漏洞远程执行命令" name_chs="利用Mantis summary_graph_functions.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Mantis summary_graph_functions.php Script Vulnerability" visible="true"/><rule ruleid="20180" enabled="true" group="136315051" action=" db  screen " name="利用site_searcher.cgi脚本漏洞远程执行命令" name_chs="利用site_searcher.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via site_searcher.cgi Script Vulnerability" visible="true"/><rule ruleid="20188" enabled="true" group="136315047" action=" db  screen " name="利用Marcus S. directory.php脚本漏洞远程执行命令" name_chs="利用Marcus S. directory.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via Marcus S. directory.php Script Vulnerability" visible="true"/><rule ruleid="40039" enabled="true" group="137429062" action=" db  screen " name="FTP服务客户端访问.rhosts文件" name_chs="FTP服务客户端访问.rhosts文件" name_eng="FTP Service Client Accessing .rhosts File" visible="true"/><rule ruleid="30479" enabled="true" group="136323133" action=" db  screen " name="QuikStore Shopping Cart quikstore.cgi脚本漏洞扫描探测" name_chs="QuikStore Shopping Cart quikstore.cgi脚本漏洞扫描探测" name_eng="QuikStore Shopping Cart quikstore.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30478" enabled="true" group="203423926" action=" db  screen " name="利用phpWebFileManager index.php脚本漏洞遍历目录攻击" name_chs="利用phpWebFileManager index.php脚本漏洞遍历目录攻击" name_eng="Directory Traversal via phpWebFileManager index.php Script Vulnerability" visible="true"/><rule ruleid="30473" enabled="true" group="138412591" action=" db  screen " name="TELNET服务暴力猜测用户口令" name_chs="TELNET服务暴力猜测用户口令" name_eng="User Password Brute Force in TELNET Service" visible="true"/><rule ruleid="40031" enabled="true" group="233898069" action=" db  screen " name="ICMP子网掩码应答消息" name_chs="ICMP子网掩码应答消息" name_eng="ICMP Netmask Response Message" visible="true"/><rule ruleid="30471" enabled="true" group="203431989" action=" db  screen " name="扫描探测MatrikzGB Guestbook脚本漏洞" name_chs="扫描探测MatrikzGB Guestbook脚本漏洞" name_eng="MatrikzGB Guestbook Script Vulnerability Detection" visible="true"/><rule ruleid="40033" enabled="true" group="146808889" action=" db  screen " name="FINGER服务代理查询操作" name_chs="FINGER服务代理查询操作" name_eng="FINGER Service Proxy Query" visible="true"/><rule ruleid="30477" enabled="true" group="136315066" action=" db  screen " name="利用CommerceSQL Shopping Cart index.cgi脚本漏洞遍历目录攻击" name_chs="利用CommerceSQL Shopping Cart index.cgi脚本漏洞遍历目录攻击" name_eng="Directory Traversal via CommerceSQL Shopping Cart index.cgi Script Vulnerability" visible="true"/><rule ruleid="30476" enabled="true" group="69214265" action=" db  screen " name="PeopleSoft PeopleTools psdoccgi.exe CGI程序漏洞扫描探测" name_chs="PeopleSoft PeopleTools psdoccgi.exe CGI程序漏洞扫描探测" name_eng="PeopleSoft PeopleTools psdoccgi.exe CGI Program Vulnerability Detection" visible="true"/><rule ruleid="40036" enabled="true" group="146808889" action=" db  screen " name="FINGER服务pipe执行命令攻击" name_chs="FINGER服务pipe执行命令攻击" name_eng="Command Execution via FINGER Service pipe" visible="true"/><rule ruleid="40037" enabled="true" group="146808889" action=" db  screen " name="FINGER服务探测“.”用户" name_chs="FINGER服务探测“.”用户" name_eng="FINGER Service &quot;.&quot; User Detection" visible="true"/><rule ruleid="40610" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Xlog木马通信" name_chs="Windows系统下Xlog木马通信" name_eng="Trojan Xlog Communication on Windows" visible="true"/><rule ruleid="40611" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Y3K木马通信" name_chs="Windows系统下Y3K木马通信" name_eng="Trojan Y3K Communication on Windows" visible="true"/><rule ruleid="40612" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下YAT木马通信" name_chs="Windows系统下YAT木马通信" name_eng="Trojan YAT Communication on Windows" visible="true"/><rule ruleid="40613" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Sober.F@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Sober.F@mm蠕虫病毒邮件" name_eng="SMTP Service Sendinng Mails with W32.Sober.F@mm" visible="true"/><rule ruleid="30309" enabled="true" group="136323126" action=" db  screen " name="ads.cgi脚本漏洞扫描利用" name_chs="ads.cgi脚本漏洞扫描利用" name_eng="ads.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="40615" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送W32.Netsky.Y@mm蠕虫病毒邮件" name_chs="SMTP服务发送W32.Netsky.Y@mm蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with W32.Netsky.Y@mm" visible="true"/><rule ruleid="40340" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下GirlFriend木马连接建立" name_chs="Windows系统下GirlFriend木马连接建立" name_eng="Trojan GirlFriend Communication on Windows" visible="true"/><rule ruleid="40341" enabled="true" group="99618895" action=" db  screen " name="Windows系统下BackOrifice 2000木马通信" name_chs="Windows系统下BackOrifice 2000木马通信" name_eng="Trojan BackOrifice 2000 Communication on Windows" visible="true"/><rule ruleid="40618" enabled="true" group="75759695" action=" db  screen " name="SMTP服务发送Plexus蠕虫病毒邮件" name_chs="SMTP服务发送Plexus蠕虫病毒邮件" name_eng="SMTP Service Sending Mails with Plexus" visible="true"/><rule ruleid="30304" enabled="true" group="136315066" action=" db  screen " name="CGIScript.NET CSSearch.cgi脚本漏洞扫描利用" name_chs="CGIScript.NET CSSearch.cgi脚本漏洞扫描利用" name_eng="CGIScript.NET CSSearch.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30307" enabled="true" group="69206206" action=" db  screen " name="Windows NT IIS MSDAC RDS远程命令执行漏洞扫描探测" name_chs="Windows NT IIS MSDAC RDS远程命令执行漏洞扫描探测" name_eng="Windows NT IIS MSDAC RDS Remote Command Execution Detection" visible="true"/><rule ruleid="30306" enabled="true" group="136315062" action=" db  screen " name="Networking_Utils.php脚本漏洞扫描利用" name_chs="Networking_Utils.php脚本漏洞扫描利用" name_eng="Networking_Utils.php Script Vulnerability Detection" visible="true"/><rule ruleid="30301" enabled="true" group="203423930" action=" db  screen " name="register.php脚本漏洞扫描利用" name_chs="register.php脚本漏洞扫描利用" name_eng="register.php Script Vulnerability Detection" visible="true"/><rule ruleid="30300" enabled="true" group="203431994" action=" db  screen " name="add-subject.php脚本漏洞扫描探测" name_chs="add-subject.php脚本漏洞扫描探测" name_eng="add-subject.php Script Vulnerability Detection" visible="true"/><rule ruleid="30303" enabled="true" group="337641654" action=" db  screen " name="Nortel Contivity cgiproc脚本漏洞扫描探测" name_chs="Nortel Contivity cgiproc脚本漏洞扫描探测" name_eng="Nortel Contivity cgiproc Script Vulnerability Detection" visible="true"/><rule ruleid="30302" enabled="true" group="69206206" action=" db  screen " name="通过Web服务访问Global.asa文件获取敏感信息" name_chs="通过Web服务访问Global.asa文件获取敏感信息" name_eng="Sensitive Information Disclosure from Global.asa File via Web Service" visible="true"/><rule ruleid="30030" enabled="true" group="146808889" action=" db  screen " name="FINGER服务查询root用户" name_chs="FINGER服务查询root用户" name_eng="FINGER Service root User Query" visible="true"/><rule ruleid="40297" enabled="true" group="68157647" action=" db  screen " name="通过Web服务利用&quot;../&quot;串遍历目录攻击" name_chs="通过Web服务利用&quot;../&quot;串遍历目录攻击" name_eng="&quot;../&quot; String Directory Traversal via Web Service" visible="true"/><rule ruleid="40290" enabled="true" group="69206206" action=" db  screen " name="Microsoft IIS远东版畸形字符编码获取文件内容攻击" name_chs="Microsoft IIS远东版畸形字符编码获取文件内容攻击" name_eng="Microsoft IIS Far East Edition Malformed Character Encoding File Content Disclosure" visible="true"/><rule ruleid="40293" enabled="true" group="69206222" action=" db  screen " name="利用..&quot;/字串突破CGI脚本过滤访问上级目录" name_chs="利用..&quot;/字串突破CGI脚本过滤访问上级目录" name_eng="CGI Script Filter Bypass And Upper Directory Access via ..&quot;/ String" visible="true"/><rule ruleid="20234" enabled="true" group="203423915" action=" db  screen " name="利用SquirrelMail left_main.php脚本漏洞远程执行命令" name_chs="利用SquirrelMail left_main.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via SquirrelMail left_main.php Script Vulnerability" visible="true"/><rule ruleid="20235" enabled="true" group="141558063" action=" db  screen  drop " name="OpenSSH挑战响应机制SKEY/BSD_AUTH验证远程缓冲区溢出攻击" name_chs="OpenSSH挑战响应机制SKEY/BSD_AUTH验证远程缓冲区溢出攻击" name_eng="OpenSSH Challenge-Response Mechanism SKEY/BSD_AUTH Authentication Remote Buffer Overflow" visible="true"/><rule ruleid="30034" enabled="true" group="233840701" action=" db  screen " name="Traceroute UDP探测网络拓扑操作" name_chs="Traceroute UDP探测网络拓扑操作" name_eng="Traceroute UDP Network Topology Detection" visible="true"/><rule ruleid="20230" enabled="true" group="69206186" action=" db  screen " name="利用Webspeed wsisa.dll CGI程序漏洞获取管理权" name_chs="利用Webspeed wsisa.dll CGI程序漏洞获取管理权" name_eng="Gaining Admin Privilege via Webspeed wsisa.dll CGI Vulnerability" visible="true"/><rule ruleid="20231" enabled="true" group="136315050" action=" db  screen " name="利用DNSTools dnstools.php脚本漏洞控制应用程序" name_chs="利用DNSTools dnstools.php脚本漏洞控制应用程序" name_eng="Application Control via DNSTools dnstools.php Script Vulnerability" visible="true"/><rule ruleid="20232" enabled="true" group="203423914" action=" db  screen " name="利用Blahz-DNS dostuff.php脚本漏洞控制应用程序" name_chs="利用Blahz-DNS dostuff.php脚本漏洞控制应用程序" name_eng="Application Control via Blahz-DNS dostuff.php Script Vulnerability" visible="true"/><rule ruleid="20233" enabled="true" group="203423915" action=" db  screen " name="利用SquirrelSpell check_me.mod.php脚本漏洞远程执行命令" name_chs="利用SquirrelSpell check_me.mod.php脚本漏洞远程执行命令" name_eng="Remote Code Execution via SquirrelSpell check_me.mod.php Script Vulnerability" visible="true"/><rule ruleid="30271" enabled="true" group="136315066" action=" db  screen " name="Sun i-Runbook none.php脚本漏洞扫描利用" name_chs="Sun i-Runbook none.php脚本漏洞扫描利用" name_eng="Sun i-Runbook none.php Script Vulnerability Detection" visible="true"/><rule ruleid="30270" enabled="true" group="203423934" action=" db  screen " name="利用NULL字节漏洞获取JRun JSP源代码攻击" name_chs="利用NULL字节漏洞获取JRun JSP源代码攻击" name_eng="JRun JSP Source Code Disclosure via NULL Byte Vulnerability" visible="true"/><rule ruleid="30273" enabled="true" group="136315066" action=" db  screen " name="Webmin edit_action.cgi脚本漏洞扫描利用" name_chs="Webmin edit_action.cgi脚本漏洞扫描利用" name_eng="Webmin edit_action.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30272" enabled="true" group="136315062" action=" db  screen " name="Matrix lastlines.cgi脚本漏洞扫描利用" name_chs="Matrix lastlines.cgi脚本漏洞扫描利用" name_eng="Matrix lastlines.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30275" enabled="true" group="136316986" action=" db  screen " name="利用//WEB-INF/漏洞获取JRun JSP源代码攻击" name_chs="利用//WEB-INF/漏洞获取JRun JSP源代码攻击" name_eng="JRun JSP Source Code Disclosure via //WEB-INF/ Vulnerabilities" visible="true"/><rule ruleid="40721" enabled="true" group="99618891" action=" db  screen " name="Windows系统下Peep木马通信" name_chs="Windows系统下Peep木马通信" name_eng="Trojan Peep Communication on Windows" visible="true"/><rule ruleid="30277" enabled="true" group="203456574" action=" db  screen " name="通过Web服务访问Trend Micro OfficeScan Virus Buster配置文件攻击" name_chs="通过Web服务访问Trend Micro OfficeScan Virus Buster配置文件攻击" name_eng="Trend Micro OfficeScan Virus Buster Config File Access via Web Service" visible="true"/><rule ruleid="30276" enabled="true" group="136323126" action=" db  screen " name="CSVForm csvform.pl脚本漏洞扫描探测" name_chs="CSVForm csvform.pl脚本漏洞扫描探测" name_eng="CSVForm csvform.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30279" enabled="true" group="136315066" action=" db  screen " name="利用Richard Lawrence faqmanager.cgi脚本漏洞读取文件攻击" name_chs="利用Richard Lawrence faqmanager.cgi脚本漏洞读取文件攻击" name_eng="Reading File via Richard Lawrence faqmanager.cgi Script Vulnerability" visible="true"/><rule ruleid="30278" enabled="true" group="136315066" action=" db  screen " name="利用Richard Lawrence faqmanager.cgi脚本漏洞遍历目录攻击" name_chs="利用Richard Lawrence faqmanager.cgi脚本漏洞遍历目录攻击" name_eng="Directory Traversal via Richard Lawrence faqmanager.cgi Script Vulnerability" visible="true"/><rule ruleid="40728" enabled="true" group="99618891" action=" db  screen " name="Windows系统下AngelShell木马通信" name_chs="Windows系统下AngelShell木马通信" name_eng="Trojan AngelShell Communication on Windows" visible="true"/><rule ruleid="40729" enabled="true" group="99618891" action=" db  screen " name="Windows系统下黑暗天使木马通信" name_chs="Windows系统下黑暗天使木马通信" name_eng="Trojan Dark Angel Communication on Windows" visible="true"/><rule ruleid="40380" enabled="true" group="166727759" action=" db  screen " name="DDOS工具Mstream主分布端连接主控端" name_chs="DDOS工具Mstream主分布端连接主控端" name_eng="Connection Between DDOS Tool Mstream Mian Distributed End and the Console" visible="true"/><rule ruleid="40508" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下F-Backdoor木马通信" name_chs="Windows系统下F-Backdoor木马通信" name_eng="Trojan F-Backdoor Communication on Windows" visible="true"/><rule ruleid="40509" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下File Nail木马通信" name_chs="Windows系统下File Nail木马通信" name_eng="Trojan File Nail Communication on Windows" visible="true"/><rule ruleid="40504" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Duddie木马通信" name_chs="Windows系统下Duddie木马通信" name_eng="Trojan Duddie Communication on Windows" visible="true"/><rule ruleid="40505" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Eclypse木马通信" name_chs="Windows系统下Eclypse木马通信" name_eng="Trojan Eclypse Communication on Windows" visible="true"/><rule ruleid="40506" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Event Horizon木马通信" name_chs="Windows系统下Event Horizon木马通信" name_eng="Trojan Event Horizon Communication on Windows" visible="true"/><rule ruleid="40507" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Exploiter木马通信" name_chs="Windows系统下Exploiter木马通信" name_eng="Trojan Exploiter Communication on Windows" visible="true"/><rule ruleid="40500" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Digital Rootbeer木马通信" name_chs="Windows系统下Digital Rootbeer木马通信" name_eng="Trojan Digital Rootbeer Communication on Windows" visible="true"/><rule ruleid="40501" enabled="true" group="99618895" action=" db  screen  drop " name="Windows系统下Doly木马通信" name_chs="Windows系统下Doly木马通信" name_eng="Trojan Doly Communication on Windows" visible="true"/><rule ruleid="40502" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Drat木马通信" name_chs="Windows系统下Drat木马通信" name_eng="Trojan Drat Communication on Windows" visible="true"/><rule ruleid="40503" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下dtr木马通信" name_chs="Windows系统下dtr木马通信" name_eng="Trojan dtr Communication on Windows" visible="true"/><rule ruleid="30099" enabled="true" group="136315066" action=" db  screen " name="CGISCRIPT.NET csNews.cgi脚本漏洞扫描探测" name_chs="CGISCRIPT.NET csNews.cgi脚本漏洞扫描探测" name_eng="CGISCRIPT.NET csNews.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30098" enabled="true" group="136315066" action=" db  screen " name="CGISCRIPT.NET csLiveSupport.cgi脚本漏洞扫描探测" name_chs="CGISCRIPT.NET csLiveSupport.cgi脚本漏洞扫描探测" name_eng="CGISCRIPT.NET csLiveSupport.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30095" enabled="true" group="136315066" action=" db  screen " name="利用Big Brother bb-hostsvc.sh脚本漏洞遍历主机目录" name_chs="利用Big Brother bb-hostsvc.sh脚本漏洞遍历主机目录" name_eng="Remote Host Directory Traversal via Big Brother bb-hostsvc.sh Script Vulnerability" visible="true"/><rule ruleid="30094" enabled="true" group="136315066" action=" db  screen " name="NCSA nph-test-cgi脚本漏洞扫描探测" name_chs="NCSA nph-test-cgi脚本漏洞扫描探测" name_eng="NCSA nph-test-cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30097" enabled="true" group="136315066" action=" db  screen " name="CGISCRIPT.NET csChatRBox.cgi脚本漏洞扫描探测" name_chs="CGISCRIPT.NET csChatRBox.cgi脚本漏洞扫描探测" name_eng="CGISCRIPT.NET csChatRBox.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30096" enabled="true" group="136315062" action=" db  screen " name="BigIP bigconf.cgi脚本漏洞扫描探测" name_chs="BigIP bigconf.cgi脚本漏洞扫描探测" name_eng="BigIP bigconf.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30090" enabled="true" group="203423934" action=" db  screen " name="获取PHP-Survey Global.INC文件攻击" name_chs="获取PHP-Survey Global.INC文件攻击" name_eng="PHP-Survey Global.INC File Disclosure" visible="true"/><rule ruleid="30093" enabled="true" group="136315062" action=" db  screen " name="Big Brother bb-hostsvc.sh脚本漏洞扫描探测" name_chs="Big Brother bb-hostsvc.sh脚本漏洞扫描探测" name_eng="Big Brother bb-hostsvc.sh Script Vulnerability Detection" visible="true"/><rule ruleid="20906" enabled="true" group="202375338" action=" db  screen " name="Caucho Resin WEB-INF目录遍历攻击" name_chs="Caucho Resin WEB-INF目录遍历攻击" name_eng="Caucho Resin WEB-INF Directory Traversal" visible="true"/><rule ruleid="20451" enabled="true" group="98566439" action=" db  screen " name="Microsoft NNTP XPAT命令远程远程缓冲区溢出攻击" name_chs="Microsoft NNTP XPAT命令远程远程缓冲区溢出攻击" name_eng="Microsoft NNTP XPAT Command Remote Buffer Overflow" visible="true"/><rule ruleid="20452" enabled="true" group="99615015" action=" db  screen " name="Microsoft Windows NetDDE远程缓冲区溢出攻击" name_chs="Microsoft Windows NetDDE远程缓冲区溢出攻击" name_eng="Microsoft Windows NetDDE Remote Buffer Overflow" visible="true"/><rule ruleid="20453" enabled="true" group="83887151" action=" db  screen  drop " name="Windows系统下MSBLAST（冲击波）蠕虫利用TFTP服务传播" name_chs="Windows系统下MSBLAST（冲击波）蠕虫利用TFTP服务传播" name_eng="Worm MSBLAST Propagation on Windows via TFTP Service" visible="true"/><rule ruleid="20454" enabled="true" group="99615791" action=" db  screen " name="Sasser（震荡波）蠕虫FTP后门操作" name_chs="Sasser（震荡波）蠕虫FTP后门操作" name_eng="Worm Sasser FTP Backdoor" visible="true"/><rule ruleid="20455" enabled="true" group="150995243" action=" db  screen " name="Solaris rpc.ttdbserverd远程栈缓冲区溢出攻击" name_chs="Solaris rpc.ttdbserverd远程栈缓冲区溢出攻击" name_eng="Solaris rpc.ttdbserverd Remote Stack Buffer Overflow" visible="true"/><rule ruleid="20457" enabled="true" group="209715499" action=" db  screen " name="SMTP服务带超长参数的EXPN命令溢出攻击" name_chs="SMTP服务带超长参数的EXPN命令溢出攻击" name_eng="SMTP Service EXPN Command with Over-long Parameters Buffer Overflow" visible="true"/><rule ruleid="40576" enabled="true" group="99618891" action=" db  screen  drop " name="Windows系统下Remote Boot木马通信" name_chs="Windows系统下Remote Boot木马通信" name_eng="Trojan Remote Boot Communication on Windows" visible="true"/><rule ruleid="10116" enabled="true" group="73402399" action=" db  screen " name="Windows NT services.exe拒绝服务攻击" name_chs="Windows NT services.exe拒绝服务攻击" name_eng="Windows NT services.exe Denial of Service" visible="true"/><rule ruleid="20510" enabled="true" group="99615015" action=" db  screen " name="Microsoft Windows消息队列服务远程缓冲区溢出攻击" name_chs="Microsoft Windows消息队列服务远程缓冲区溢出攻击" name_eng="Microsoft Windows Message Queuing Service Remote Buffer Overflow" visible="true"/><rule ruleid="30214" enabled="true" group="69206205" action=" db  screen " name="利用Microsoft IIS .idq ISAPI扩展获取绝对路径攻击" name_chs="利用Microsoft IIS .idq ISAPI扩展获取绝对路径攻击" name_eng="Absolute Path Disclosure via Microsoft IIS .idq ISAPI Extension" visible="true"/><rule ruleid="10114" enabled="true" group="70256671" action=" db  screen  drop " name="Serv-U FTP服务器设备文件名远程拒绝服务攻击" name_chs="Serv-U FTP服务器设备文件名远程拒绝服务攻击" name_eng="Serv-U FTP Server Device Filename Remote Denial of Service" visible="true"/><rule ruleid="10115" enabled="true" group="233834527" action=" db  screen " name="UDP-Flood淹没拒绝服务攻击" name_chs="UDP-Flood淹没拒绝服务攻击" name_eng="UDP-Flood Denial of Service Attacks" visible="true"/><rule ruleid="78999" enabled="true" group="368115781" action="" name="FTP服务root用户" name_chs="FTP服务root用户" name_eng="FTP Service root Account" visible="false"/><rule ruleid="20515" enabled="true" group="76546347" action=" db  screen " name="IMAP服务程序CREATE命令远程缓冲区溢出攻击" name_chs="IMAP服务程序CREATE命令远程缓冲区溢出攻击" name_eng="IMAP Server CREATE Command Remote Buffer Overflow" visible="true"/><rule ruleid="20514" enabled="true" group="203423915" action=" db  screen " name="PunBB profile.php temp变量远程SQL注入攻击" name_chs="PunBB profile.php temp变量远程SQL注入攻击" name_eng="PunBB profile.php temp Variable Remote SQL Injection" visible="true"/><rule ruleid="10110" enabled="true" group="233832731" action=" db  screen " name="ISS RealSecure/BlackICE协议分析模块SMB解析堆溢出攻击" name_chs="ISS RealSecure/BlackICE协议分析模块SMB解析堆溢出攻击" name_eng="ISS RealSecure/BlackICE Protocol Analysis Module SMB Resolution Heap Overflow" visible="true"/><rule ruleid="10049" enabled="true" group="69206174" action=" db  screen " name="ExAir示例脚本query.asp拒绝服务攻击" name_chs="ExAir示例脚本query.asp拒绝服务攻击" name_eng="ExAir Sample Script query.asp Denial of Service" visible="true"/><rule ruleid="10044" enabled="true" group="69208095" action=" db  screen " name="Microsoft FrontPage shtml.exe恶意访问攻击" name_chs="Microsoft FrontPage shtml.exe恶意访问攻击" name_eng="Microsoft FrontPage shtml.exe Malicious Access" visible="true"/><rule ruleid="10045" enabled="true" group="69208095" action=" db  screen " name="Microsoft FrontPage shtml.dll恶意访问攻击" name_chs="Microsoft FrontPage shtml.dll恶意访问攻击" name_eng="Microsoft FrontPage shtml.dll Malicious Access" visible="true"/><rule ruleid="10046" enabled="true" group="73402399" action=" db  screen  drop " name="Microsoft网络共享器SMB请求远程拒绝服务攻击" name_chs="Microsoft网络共享器SMB请求远程拒绝服务攻击" name_eng="Microsoft Share Provider SMB Request Remote Denial of Service" visible="true"/><rule ruleid="20759" enabled="true" group="203423914" action=" db  screen " name="Stylemotion WEB//NEWS多个远程SQL注入攻击" name_chs="Stylemotion WEB//NEWS多个远程SQL注入攻击" name_eng="Stylemotion WEB//NEWS multiple Remote SQL Injections" visible="true"/><rule ruleid="20758" enabled="true" group="203423914" action=" db  screen " name="PHP-Nuke多个模块远程SQL注入攻击" name_chs="PHP-Nuke多个模块远程SQL注入攻击" name_eng="PHP-Nuke multiple Modules Remote SQL Injection" visible="true"/><rule ruleid="20753" enabled="true" group="203423914" action=" db  screen " name="Revize CMS query_results.jsp远程SQL注入攻击" name_chs="Revize CMS query_results.jsp远程SQL注入攻击" name_eng="Revize CMS query_results.jsp Remote SQL Injection" visible="true"/><rule ruleid="20752" enabled="true" group="203423914" action=" db  screen " name="Google搜索工具ProxyStyleSheet远程文件包含攻击" name_chs="Google搜索工具ProxyStyleSheet远程文件包含攻击" name_eng="Google Search Appliance ProxyStyleSheet Remote File Inclusion" visible="true"/><rule ruleid="20751" enabled="true" group="203423914" action=" db  screen " name="PluggedOut Blog index.php远程SQL注入攻击" name_chs="PluggedOut Blog index.php远程SQL注入攻击" name_eng="PluggedOut Blog index.php Remote SQL Injection" visible="true"/><rule ruleid="20750" enabled="true" group="203423914" action=" db  screen " name="Cars Portal index.php远程SQL注入攻击" name_chs="Cars Portal index.php远程SQL注入攻击" name_eng="Cars Portal index.php Remote SQL Injection" visible="true"/><rule ruleid="20757" enabled="true" group="70254890" action=" db  screen " name="FTP服务器USER命令超长参数远程缓冲区溢出攻击" name_chs="FTP服务器USER命令超长参数远程缓冲区溢出攻击" name_eng="FTP Server USER Command Over-long Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20756" enabled="true" group="203423914" action=" db  screen " name="Xoops多个脚本远程SQL注入攻击" name_chs="Xoops多个脚本远程SQL注入攻击" name_eng="Xoops multiple Scripts Remote SQL Injection" visible="true"/><rule ruleid="20755" enabled="true" group="203423914" action=" db  screen " name="Wizz Forum多个脚本远程SQL注入攻击" name_chs="Wizz Forum多个脚本远程SQL注入攻击" name_eng="Wizz Forum multiple Scripts Remote SQL Injection" visible="true"/><rule ruleid="20754" enabled="true" group="203423914" action=" db  screen " name="Unclassified NewsBoard forum.php远程SQL注入攻击" name_chs="Unclassified NewsBoard forum.php远程SQL注入攻击" name_eng="Unclassified NewsBoard forum.php Remote SQL Injection" visible="true"/><rule ruleid="20537" enabled="true" group="99615019" action=" db  screen " name="CA Unicenter CAM log_security()远程缓冲区溢出攻击" name_chs="CA Unicenter CAM log_security()远程缓冲区溢出攻击" name_eng="CA Unicenter CAM log_security() Remote Buffer Overflow" visible="true"/><rule ruleid="10135" enabled="true" group="99616799" action=" db  screen  drop " name="Microsoft Windows畸形IGMPv3报文远程拒绝服务攻击" name_chs="Microsoft Windows畸形IGMPv3报文远程拒绝服务攻击" name_eng="Microsoft Windows Malformed IGMPv3 Message Remote Denial of Service" visible="true"/><rule ruleid="10136" enabled="true" group="99616799" action=" db  screen " name="传奇克星拒绝服务攻击" name_chs="传奇克星拒绝服务攻击" name_eng="Legend Terminator Denial of Service" visible="true"/><rule ruleid="10137" enabled="true" group="95422495" action=" db  screen " name="Microsoft Windows SMB srv.sys空指针引用远程拒绝服务攻击" name_chs="Microsoft Windows SMB srv.sys空指针引用远程拒绝服务攻击" name_eng="Microsoft Windows SMB srv.sys Null Pointer Reference Remote Denial of Service" visible="true"/><rule ruleid="10130" enabled="true" group="233834527" action=" db  screen  drop " name="多家厂商TCP/IP协议栈实现ICMP重置TCP连接拒绝服务攻击" name_chs="多家厂商TCP/IP协议栈实现ICMP重置TCP连接拒绝服务攻击" name_eng="Many Vendors TCP/IP Protocol Stack Implementation ICMP Reset TCP Connection Denial of Service" visible="true"/><rule ruleid="20532" enabled="true" group="136315055" action=" db  screen " name="TWiki rev参数远程执行命令攻击" name_chs="TWiki rev参数远程执行命令攻击" name_eng="TWiki rev Parameter Remote Command Execution" visible="true"/><rule ruleid="20531" enabled="true" group="99615019" action=" db  screen " name="DameWare Mini Remote Control Server预认证用户名溢出攻击" name_chs="DameWare Mini Remote Control Server预认证用户名溢出攻击" name_eng="DameWare Mini Remote Control Server Pre-authentication Username Overflow" visible="true"/><rule ruleid="10133" enabled="true" group="156239899" action=" db  screen " name="Sun Solaris LPD删除系统文件攻击" name_chs="Sun Solaris LPD删除系统文件攻击" name_eng="Sun Solaris LPD System File Deletion" visible="true"/><rule ruleid="10138" enabled="true" group="166725659" action=" db  screen " name="FreeBSD nfsd畸形mount请求远程拒绝服务攻击" name_chs="FreeBSD nfsd畸形mount请求远程拒绝服务攻击" name_eng="FreeBSD nfsd Malformed mount Request Remote Denial of Service" visible="true"/><rule ruleid="10139" enabled="true" group="160434203" action=" db  screen " name="Linux Kernel SNMP NAT Helper远程拒绝服务攻击" name_chs="Linux Kernel SNMP NAT Helper远程拒绝服务攻击" name_eng="Linux Kernel SNMP NAT Helper Remote Denial of Service" visible="true"/><rule ruleid="20538" enabled="true" group="69206311" action=" db  screen " name="RSA SecurID Web Agent for IIS ISAPI远程缓冲区溢出攻击" name_chs="RSA SecurID Web Agent for IIS ISAPI远程缓冲区溢出攻击" name_eng="RSA SecurID Web Agent for IIS ISAPI Remote Buffer Overflow" visible="true"/><rule ruleid="40191" enabled="true" group="70262842" action=" db  screen " name="通过Web服务访问ws_ftp.ini文件" name_chs="通过Web服务访问ws_ftp.ini文件" name_eng="Access to ws_ftp.ini File via Web Service" visible="true"/><rule ruleid="20403" enabled="true" group="69206187" action=" db  screen " name="利用Cart32 cart32.exe CGI漏洞获取口令" name_chs="利用Cart32 cart32.exe CGI漏洞获取口令" name_eng="Password Disclosure via Cart32 cart32.exe CGI Vulnerability" visible="true"/><rule ruleid="20402" enabled="true" group="136315045" action=" db  screen " name="利用Squid cachemgr.cgi脚本漏洞非授权连接主机" name_chs="利用Squid cachemgr.cgi脚本漏洞非授权连接主机" name_eng="Unauthorized Host Connection via Squid cachemgr.cgi Script Vulnerability" visible="true"/><rule ruleid="20401" enabled="true" group="68157607" action=" db  screen " name="利用Web服务器处理请求文件名漏洞执行命令攻击" name_chs="利用Web服务器处理请求文件名漏洞执行命令攻击" name_eng="Requested Filename Handling via web Server Command Execution" visible="true"/><rule ruleid="20400" enabled="true" group="69206319" action=" db  screen " name="Windows Media服务NSIISlog.DLL超长MX_STATS_LogLine参数远程缓冲区溢出攻击" name_chs="Windows Media服务NSIISlog.DLL超长MX_STATS_LogLine参数远程缓冲区溢出攻击" name_eng="Windows Media Service NSIISlog.DLL Over-long MX_STATS_LogLine Parameter Remote Buffer Overflow" visible="true"/><rule ruleid="20407" enabled="true" group="135266607" action=" db  screen  drop " name="Apache Web Server分块编码传输方式远程溢出攻击" name_chs="Apache Web Server分块编码传输方式远程溢出攻击" name_eng="Apache Web Server Chunked Encoding Transmission Remote Buffer Overflow" visible="true"/><rule ruleid="20406" enabled="true" group="69206315" action=" db  screen " name="Allaire JRun超长JSP文件名溢出攻击" name_chs="Allaire JRun超长JSP文件名溢出攻击" name_eng="Allaire JRun Over-long JSP Filename Buffer Overflow" visible="true"/><rule ruleid="20405" enabled="true" group="69206315" action=" db  screen " name="Allaire Forums超长CFM文件名溢出攻击" name_chs="Allaire Forums超长CFM文件名溢出攻击" name_eng="Allaire Forums Over-long CFM Filename Buffer Overflow" visible="true"/><rule ruleid="20404" enabled="true" group="69206187" action=" db  screen " name="利用Cart32 cart32.exe CGI漏洞收集系统信息" name_chs="利用Cart32 cart32.exe CGI漏洞收集系统信息" name_eng="System Information Disclosure via Cart32 cart32.exe CGI Vulnerability" visible="true"/><rule ruleid="20409" enabled="true" group="204472619" action=" db  screen " name="FTP服务LIST命令超长参数溢出攻击" name_chs="FTP服务LIST命令超长参数溢出攻击" name_eng="FTP Service LIST Command Over-long Parameter Buffer Overflow" visible="true"/><rule ruleid="20408" enabled="true" group="204472619" action=" db  screen " name="FTP服务DELE命令超长参数溢出攻击" name_chs="FTP服务DELE命令超长参数溢出攻击" name_eng="FTP Service DELE Command Over-long Parameter Buffer Overflow" visible="true"/><rule ruleid="30464" enabled="true" group="136323129" action=" db  screen " name="Geeklog users.php脚本漏洞扫描探测" name_chs="Geeklog users.php脚本漏洞扫描探测" name_eng="Geeklog users.php Script Vulnerability Detection" visible="true"/><rule ruleid="30465" enabled="true" group="69214262" action=" db  screen " name="Philboard philboard_admin.asp脚本漏洞扫描探测" name_chs="Philboard philboard_admin.asp脚本漏洞扫描探测" name_eng="Philboard philboard_admin.asp Script Vulnerability Detection" visible="true"/><rule ruleid="30466" enabled="true" group="203431994" action=" db  screen " name="phpBB admin_styles.php脚本漏洞扫描探测" name_chs="phpBB admin_styles.php脚本漏洞扫描探测" name_eng="phpBB admin_styles.php Script Vulnerability Detection" visible="true"/><rule ruleid="30460" enabled="true" group="136323126" action=" db  screen " name="HappyMall E-Commerce normal_html.cgi脚本漏洞扫描探测" name_chs="HappyMall E-Commerce normal_html.cgi脚本漏洞扫描探测" name_eng="HappyMall E-Commerce normal_html.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30461" enabled="true" group="136323126" action=" db  screen " name="BLNews objects.inc.php4脚本漏洞扫描探测" name_chs="BLNews objects.inc.php4脚本漏洞扫描探测" name_eng="BLNews objects.inc.php4 Script Vulnerability Detection" visible="true"/><rule ruleid="30462" enabled="true" group="203431994" action=" db  screen " name="Ultimate PHP Board admin_iplog.php脚本漏洞扫描探测" name_chs="Ultimate PHP Board admin_iplog.php脚本漏洞扫描探测" name_eng="Ultimate PHP Board admin_iplog.php Script Vulnerability Detection" visible="true"/><rule ruleid="30463" enabled="true" group="203431993" action=" db  screen " name="shoutbox脚本漏洞扫描探测" name_chs="shoutbox脚本漏洞扫描探测" name_eng="shoutbox Script Vulnerability Detection" visible="true"/><rule ruleid="40372" enabled="true" group="137429062" action=" db  screen " name="FTP服务客户端访问.forward文件" name_chs="FTP服务客户端访问.forward文件" name_eng="FTP Service Client Accessing .forward File" visible="true"/><rule ruleid="40371" enabled="true" group="137429062" action=" db  screen " name="FTP服务客户端访问UNIX口令文件" name_chs="FTP服务客户端访问UNIX口令文件" name_eng="FTP Service Client Accessing UNIX Password File" visible="true"/><rule ruleid="40370" enabled="true" group="137429062" action=" db  screen " name="FTP服务客户端访问.shosts文件" name_chs="FTP服务客户端访问.shosts文件" name_eng="FTP Service Client Accessing .shosts File" visible="true"/><rule ruleid="40377" enabled="true" group="166727759" action=" db  screen " name="DDOS工具TFN主控端向分布端发送指令" name_chs="DDOS工具TFN主控端向分布端发送指令" name_eng="DDOS Tool TFN Console Sending Command to Distributed End" visible="true"/><rule ruleid="40376" enabled="true" group="166727759" action=" db  screen " name="DDOS工具TFN2K主控端向分布端发送指令" name_chs="DDOS工具TFN2K主控端向分布端发送指令" name_eng="DDOS Tool TFN2K Console Sending Command to Distributed End" visible="true"/><rule ruleid="30318" enabled="true" group="136315066" action=" db  screen " name="利用web_store.cgi脚本漏洞遍历目录攻击" name_chs="利用web_store.cgi脚本漏洞遍历目录攻击" name_eng="Directory Traversal via web_store.cgi Script Vulnerability" visible="true"/><rule ruleid="30319" enabled="true" group="136315062" action=" db  screen " name="cgiforum.pl脚本漏洞扫描利用" name_chs="cgiforum.pl脚本漏洞扫描利用" name_eng="cgiforum.pl Script Vulnerability Detection" visible="true"/><rule ruleid="30316" enabled="true" group="69206202" action=" db  screen " name="IRIX windmail.exe程序漏洞扫描利用" name_chs="IRIX windmail.exe程序漏洞扫描利用" name_eng="IRIX windmail.exe Vulnerability Detection" visible="true"/><rule ruleid="30317" enabled="true" group="136323130" action=" db  screen " name="web_store.cgi脚本漏洞扫描探测" name_chs="web_store.cgi脚本漏洞扫描探测" name_eng="web_store.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30314" enabled="true" group="136316986" action=" db  screen " name="Tomcat 3.0远程目录遍历攻击" name_chs="Tomcat 3.0远程目录遍历攻击" name_eng="Tomcat 3.0 Remote Directory Traversal" visible="true"/><rule ruleid="30315" enabled="true" group="136315066" action=" db  screen " name="IRIX infosrch.cgi脚本漏洞扫描利用" name_chs="IRIX infosrch.cgi脚本漏洞扫描利用" name_eng="IRIX infosrch.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30312" enabled="true" group="202377274" action=" db  screen " name="利用weblogic漏洞获取JSP脚本源码攻击" name_chs="利用weblogic漏洞获取JSP脚本源码攻击" name_eng="JSP Script Source Code Disclosure via weblogic Vulnerability" visible="true"/><rule ruleid="30313" enabled="true" group="203425850" action=" db  screen " name="利用Tomcat漏洞获取JSP脚本源码攻击" name_chs="利用Tomcat漏洞获取JSP脚本源码攻击" name_eng="JSP Source Code Disclosure via Tomcat Vulnerabilities" visible="true"/><rule ruleid="30310" enabled="true" group="136315062" action=" db  screen " name="main.cgi脚本漏洞扫描利用" name_chs="main.cgi脚本漏洞扫描利用" name_eng="main.cgi Script Vulnerability Detection" visible="true"/><rule ruleid="30186" enabled="true" group="203423931" action=" db  screen " name="利用EZShopper loadpage.cgi脚本漏洞远程执行命令" name_chs="利用EZShopper loadpage.cgi脚本漏洞远程执行命令" name_eng="Remote Code Execution via EZShopper loadpage.cgi Script Vulnerability" visible="true"/><rule ruleid="29001" enabled="true" group="203423914" action=" db  screen " name="WEB服务远程SQL注入攻击" name_chs="WEB服务远程SQL注入攻击" name_eng="WEB Service Remote SQL Injection" visible="true"/><rule ruleid="29002" enabled="true" group="203423914" action=" db  screen " name="WEB服务远程跨站脚本执行攻击" name_chs="WEB服务远程跨站脚本执行攻击" name_eng="WEB Service Remote Cross-Site Scripting" visible="true"/><rule ruleid="20356" enabled="true" group="141558063" action=" db  screen " name="SSH守护程序缓冲区溢出攻击" name_chs="SSH守护程序缓冲区溢出攻击" name_eng="SSH Daemon Buffer Overflow" visible="true"/><rule ruleid="20241" enabled="true" group="136315047" action=" db  screen " name="RedHat Piranha passwd.php3 CGI漏洞扫描利用" name_chs="RedHat Piranha passwd.php3 CGI漏洞扫描利用" name_eng="RedHat Piranha passwd.php3 CGI Vulnerability Detection" visible="true"/><rule ruleid="20240" enabled="true" group="136315047" action=" db  screen " name="count.cgi脚本漏洞扫描探测" name_chs="count.cgi脚本
