<?xml version="1.0" encoding="iso-8859-15" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns="http://purl.org/rss/1.0/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:wiki="http://purl.org/rss/1.0/modules/wiki/" ><channel rdf:about="http://doc.bleedingthreats.net/bin/view/Main">
<title>Bleeding Edge Threats Documentation</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main</link>
  <description>Bleeding Edge Threats Documentation Changes</description>
<p />
<!-- <ul>
<li> Set SKIN = rss
</li></ul> 
-->
<image rdf:resource="http://doc.bleedingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif" />
  <dc:language>en-us</dc:language>
  <dc:rights>Copyright 2008 by Bleeding Edge Threats</dc:rights>
  <dc:publisher>BE Doc Team [doc@bleedingthreats.net]</dc:publisher>
  <dc:creator>Bleeding Edge Threats</dc:creator>
  <dc:source>TWiki</dc:source>
  <items>
    <rdf:Seq>
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/LordD" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/SherryZhou" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/AmirabasZebhi" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/AntonioDelgadillo" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/JohnDoe" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/MehdiHosseinzadeh" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/HamidKashfi" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/ChenXinming" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/2003394" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/PaulJohnson" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/PatrickOToole" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/SergeyZakamarko" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/SnortConfSamples" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/YuichiSasaki" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/HurYoon" />
      <rdf:li rdf:resource="http://doc.bleedingthreats.net/bin/view/Main/Chinabaiteman" />
    </rdf:Seq>
  </items>
</channel>
<image rdf:about="http://doc.bleedingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif">
  <title>Powered by TWiki.Main</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main</link>
  <url>http://doc.bleedingthreats.net/pub/TWiki/TWikiLogos/T-logo-140x40-t.gif</url>
</image>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2003394">
  <title>2003394</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2003394</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE MALWARE User Agent Containing http\:// Suspicious Likely Spyware/Trojan"; flow:to server ... (last changed by PaulJohnson)</description>
  <dc:date>2008-08-12T03:22:37Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.PaulJohnson">
      <rdf:value>PaulJohnson</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/SnortConfSamples">
  <title>SnortConfSamples</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/SnortConfSamples</link>
  <description>Snort.Conf Samples The goal of this project is to make a set of sample snort.conf files. These will represent different size and goal installs of snort. We do not ... (last changed by JamesMcQuaid)</description>
  <dc:date>2008-07-14T11:06:25Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.JamesMcQuaid">
      <rdf:value>JamesMcQuaid</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/FastFluxDNSResponseDetection">
  <title>FastFluxDNSResponseDetection</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/FastFluxDNSResponseDetection</link>
  <description>JohnMcCash 10 Jan 2008 I have a question for the BleedingThreats audience at large. I was just reading up a bit on Fast Flux DNS configurations, which are being ... (last changed by CurtWilson)</description>
  <dc:date>2008-03-05T20:50:22Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.CurtWilson">
      <rdf:value>CurtWilson</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007634">
  <title>2007634</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007634</link>
  <description>alert udp $HOME NET 1024:65535 $EXTERNAL NET 1024:65535 (msg:"BLEEDING EDGE TROJAN Storm Worm Encrypted Traffic Outbound Likely Search by md5"; dsize:25; threshold ... (last changed by MikeSchroll)</description>
  <dc:date>2008-02-20T19:43:17Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.MikeSchroll">
      <rdf:value>MikeSchroll</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/DilipPatel">
  <title>DilipPatel</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/DilipPatel</link>
  <description>My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ... (last changed by TWikiRegistrationAgent)</description>
  <dc:date>2008-01-11T12:12:02Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiRegistrationAgent">
      <rdf:value>TWikiRegistrationAgent</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/TestTest123">
  <title>TestTest123</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/TestTest123</link>
  <description>My Links .ATasteOfTWiki view a short introductory presentation on TWiki for beginners .WelcomeGuest starting points on TWiki .TWikiUsersGuide ... (last changed by TWikiRegistrationAgent)</description>
  <dc:date>2008-01-11T08:36:34Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiRegistrationAgent">
      <rdf:value>TWikiRegistrationAgent</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2003642">
  <title>2003642</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2003642</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Downloader.Affill User Agent Detected (lol)"; flow:established,to server; content: ... (last changed by RegQuinton)</description>
  <dc:date>2007-12-21T19:41:55Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.RegQuinton">
      <rdf:value>RegQuinton</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007588">
  <title>2007588</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007588</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Win32 ALT C C Initial Infection Checkin"; flow:established,to server; dsize:18; content ... (last changed by TomH)</description>
  <dc:date>2007-12-20T20:39:01Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TomH">
      <rdf:value>TomH</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007688">
  <title>2007688</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007688</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE TROJAN Prg Trojan HTTP POST"; flow:established,to server; content:"POST "; depth:5; uricontent ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-18T00:01:37Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007706">
  <title>2007706</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007706</link>
  <description>alert udp $HOME NET 1024: $EXTERNAL NET 4099 (msg:"BLEEDING EDGE TROJAN Srizbi registering with controller"; dsize:20; content:" 2d "; offset:6; content:" 2d ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-13T17:01:25Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007707">
  <title>2007707</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007707</link>
  <description>alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.com"; content:" 04 wpad 03 com 02 "; nocase; reference:url,support ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-13T05:46:02Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007709">
  <title>2007709</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007709</link>
  <description>alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.net"; content:" 04 wpad 03 net 02 "; nocase; reference:url,support ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-13T05:46:02Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007710">
  <title>2007710</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007710</link>
  <description>alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.org"; content:" 04 wpad 03 org 02 "; nocase; reference:url,support ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-13T05:46:02Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007708">
  <title>2007708</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007708</link>
  <description>alert udp $HOME NET any $DNS SERVERS 53 (msg:"BLEEDING EDGE DNS Possible MITM lookup for WPAD.co"; content:" 04 wpad 02 co 02 "; nocase; reference:url,support.microsoft ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-13T05:46:02Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007705">
  <title>2007705</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007705</link>
  <description>alert tcp $HOME NET any $EXTERNAL NET $HTTP PORTS (msg:"BLEEDING EDGE WEB Neosploit 1.5.x URL Loader"; flow:to server,established; content:"GET "; depth:4; nocase ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-13T05:31:05Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/AllProjects">
  <title>AllProjects</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/AllProjects</link>
  <description>Bleeding Edge Threats Projects This page indexes the projects hosted at or closely connected and supported by the Bleeding Edge Threats Community. We highly encourage ... (last changed by DavidTaylor)</description>
  <dc:date>2007-12-06T23:35:07Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.DavidTaylor">
      <rdf:value>DavidTaylor</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2003484">
  <title>2003484</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2003484</link>
  <description>alert tcp any any any $HTTP PORTS (msg:"BLEEDING EDGE WORM Allaple Unique HTTP Request Possibly part of DDOS"; flow:established,to server; content:"GET / HTTP ... (last changed by TrinidadMontano)</description>
  <dc:date>2007-12-06T15:55:04Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TrinidadMontano">
      <rdf:value>TrinidadMontano</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007703">
  <title>2007703</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007703</link>
  <description>alert tcp $EXTERNAL NET any $HOME NET any (msg: "BLEEDING EDGE WEB CLIENT Apple Quicktime RTSP Content Type overflow attempt"; flow:established,from server; content ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-04T00:16:47Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2007704">
  <title>2007704</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2007704</link>
  <description>alert udp $EXTERNAL NET any $HOME NET any (msg: "BLEEDING EDGE WEB CLIENT Apple Quicktime RTSP Content Type overflow attempt"; content:"RTSP/"; nocase; depth:5 ... (last changed by TWikiGuest)</description>
  <dc:date>2007-12-04T00:16:47Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item>
<item rdf:about="http://doc.bleedingthreats.net/bin/view/Main/2003174">
  <title>2003174</title>
  <link>http://doc.bleedingthreats.net/bin/view/Main/2003174</link>
  <description>alert tcp $EXTERNAL NET $HTTP PORTS $HOME NET any (msg:"BLEEDING EDGE EXPLOIT Possible UTF 16 encoded Shellcode Detected";flow:from server,established;pcre:"/( ... (last changed by TWikiGuest)</description>
  <dc:date>2007-11-28T23:31:07Z</dc:date>
  <dc:contributor>
    <rdf:Description link="http://doc.bleedingthreats.net/bin/view?topic=Main.TWikiGuest">
      <rdf:value>guest</rdf:value>
    </rdf:Description>
  </dc:contributor>
</item></rdf:RDF>