<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="de">
	<id>https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Vorlage%3ASuricata-rules</id>
	<title>Vorlage:Suricata-rules - Versionsgeschichte</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ixheim.de/index.php?action=history&amp;feed=atom&amp;title=Vorlage%3ASuricata-rules"/>
	<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;action=history"/>
	<updated>2026-05-14T17:06:32Z</updated>
	<subtitle>Versionsgeschichte dieser Seite in Xinux Wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69264&amp;oldid=prev</id>
		<title>Thomas.will am 30. April 2026 um 10:45 Uhr</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69264&amp;oldid=prev"/>
		<updated>2026-04-30T10:45:21Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 30. April 2026, 10:45 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l23&quot; &gt;Zeile 23:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 23:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -sS -p1-100 10.88.2XX.21&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -sS -p1-100 10.88.2XX.21&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp any any -&amp;gt; any any (msg:&amp;quot;OWN SCAN TCP SYN sweep&amp;quot;; flow:stateless,to_server; flags:S; detection_filter:track by_src,count 20,seconds 5; classtype:attempted-recon; sid:9000060; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp any any -&amp;gt; any any (msg:&amp;quot;OWN SCAN TCP SYN sweep&amp;quot;; flow:stateless,to_server; flags:S; detection_filter:track by_src,count 20,seconds 5; classtype:attempted-recon; sid:9000060; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# Scan: TCP NULL-Scan (keine Flags gesetzt)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# Test: nmap -sN -p1-100 10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;drop tcp any any -&amp;gt; any any (msg:&amp;quot;OWN SCAN TCP NULL scan&amp;quot;; flow:stateless,to_server; flags:0; detection_filter:track by_src,count 5,seconds 10; classtype:attempted-recon; sid:9000061; rev:1;)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: UDP-Sweep mit leerer Payload&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: UDP-Sweep mit leerer Payload&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l33&quot; &gt;Zeile 33:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 37:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Brute Force SSH&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Brute Force SSH&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: hydra -l &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;root &lt;/del&gt;-P &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;/usr/share/wordlists/rockyou.txt &lt;/del&gt;ssh://10.88.2XX.21&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: hydra -l &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;kit &lt;/ins&gt;-P &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;bad-passwords &lt;/ins&gt;ssh://10.88.2XX.21&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp any any -&amp;gt; any 22 (msg:&amp;quot;OWN SSH Brute Force&amp;quot;; flow:to_server,stateless; flags:S; detection_filter:track by_src,count 10,seconds 60; classtype:attempted-recon; sid:9000066; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp any any -&amp;gt; any 22 (msg:&amp;quot;OWN SSH Brute Force&amp;quot;; flow:to_server,stateless; flags:S; detection_filter:track by_src,count 10,seconds 60; classtype:attempted-recon; sid:9000066; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key my_wiki:diff::1.12:old-69258:rev-69264 --&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69258&amp;oldid=prev</id>
		<title>Thomas.will am 30. April 2026 um 10:38 Uhr</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69258&amp;oldid=prev"/>
		<updated>2026-04-30T10:38:22Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 30. April 2026, 10:38 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot; &gt;Zeile 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# ICMP: einfacher Ping/Traceroute (schneller Funktionstest)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# ICMP: einfacher Ping/Traceroute (schneller Funktionstest)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: ping -&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;c1 &amp;lt;ZIEL&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: ping -&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;c 1 1.1.1.1&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert icmp any any -&amp;gt; any any (msg:&amp;quot;ICMP Test&amp;quot;; classtype:misc-activity; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;41&lt;/del&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert icmp any any -&amp;gt; any any (msg:&amp;quot;ICMP Test&amp;quot;; classtype:misc-activity; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000041&lt;/ins&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# HTTP: mögliches Command-Injection-Merkmal (Semikolon) in POST-Body&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# HTTP: mögliches Command-Injection-Merkmal (Semikolon) in POST-Body&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: curl -X POST http://&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;ZIEL&amp;gt;&lt;/del&gt;/ -d &amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;q&lt;/del&gt;=&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;test%3Bls&lt;/del&gt;&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: curl -X POST http://&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;www.it2XX.int&lt;/ins&gt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;host.php --data-urlencode &amp;quot;fqdn=example.com;ls&amp;quot; &lt;/ins&gt;-d &amp;quot;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;submit&lt;/ins&gt;=&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Auflösen&lt;/ins&gt;&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert http any any -&amp;gt; any any (msg:&amp;quot;Command Injection - Semicolon in POST DATA&amp;quot;; classtype:web-application-attack; flow:established; content:&amp;quot;%3B&amp;quot;; nocase; http_client_body; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;2&lt;/del&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert http any any -&amp;gt; any any (msg:&amp;quot;Command Injection - Semicolon in POST DATA&amp;quot;; classtype:web-application-attack; flow:established; content:&amp;quot;%3B&amp;quot;; nocase; http_client_body; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000002&lt;/ins&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# HTTP: mögliches SQLi-Merkmal (einfaches Hochkomma) in POST-Body&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# HTTP: mögliches SQLi-Merkmal (einfaches Hochkomma) in POST-Body&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: curl -X POST http://&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;ZIEL&amp;gt;&lt;/del&gt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;login &lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;d &lt;/del&gt;&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;u&lt;/del&gt;=&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;a&amp;amp;p&lt;/del&gt;='&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;%20OR%201=&lt;/del&gt;1&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: curl -X POST http://&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;www.it2XX.int&lt;/ins&gt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sql-classic.php -&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;data-urlencode &lt;/ins&gt;&amp;quot;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;username&lt;/ins&gt;=&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;' OR '1'&lt;/ins&gt;='1&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;' --&lt;/ins&gt;&amp;quot;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert http any any -&amp;gt; any any (msg:&amp;quot;Possible SQL Injection (singlequote in POST)&amp;quot;; classtype:web-application-attack; flow:established,to_server; content:&amp;quot;%27&amp;quot;; nocase; http_client_body; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;3&lt;/del&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert http any any -&amp;gt; any any (msg:&amp;quot;Possible SQL Injection (singlequote in POST)&amp;quot;; classtype:web-application-attack; flow:established,to_server; content:&amp;quot;%27&amp;quot;; nocase; http_client_body; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000003&lt;/ins&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# DNS: Policy &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;– &lt;/del&gt;verbietet &amp;quot;google&amp;quot; in DNS-Queries&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# DNS: Policy &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;- &lt;/ins&gt;verbietet &amp;quot;google&amp;quot; in DNS-Queries&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;dig &lt;/del&gt;google.&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;com @&amp;lt;FW&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;host &lt;/ins&gt;google.&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;de&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop dns any any -&amp;gt; any any (msg:&amp;quot;Kein Googlen&amp;quot;; dns.query; content:&amp;quot;google&amp;quot;; nocase; classtype:policy-violation; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;43&lt;/del&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop dns any any -&amp;gt; any any (msg:&amp;quot;Kein Googlen&amp;quot;; dns.query; content:&amp;quot;google&amp;quot;; nocase; classtype:policy-violation; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000043&lt;/ins&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# DoS: viele identische kurze HTTP-GETs (LOIC-ähnlich)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# DoS: viele identische kurze HTTP-GETs (LOIC-ähnlich)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: ab -n 1000 -c 500 http://&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;ZIEL&amp;gt;&lt;/del&gt;/&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: ab -n 1000 -c 500 http://&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;www.it2XX.int&lt;/ins&gt;/&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp any any -&amp;gt; any any (msg:&amp;quot;ET DOS Terse HTTP GET Likely LOIC&amp;quot;; flow:to_server,established; dsize:18; content:&amp;quot;GET / HTTP/1.1|0d 0a 0d 0a|&amp;quot;; depth:18; threshold:type both,track by_dst,count 500,seconds 60; classtype:own-dos; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;54&lt;/del&gt;; rev:2&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;; metadata:created_at 2014_10_03, confidence Medium, signature_severity Major, updated_at 2019_07_26&lt;/del&gt;;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp any any -&amp;gt; any any (msg:&amp;quot;ET DOS Terse HTTP GET Likely LOIC&amp;quot;; flow:to_server,established; dsize:18; content:&amp;quot;GET / HTTP/1.1|0d 0a 0d 0a|&amp;quot;; depth:18; threshold:type both,track by_dst,count 500,seconds 60; classtype:own-dos; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000054&lt;/ins&gt;; rev:2;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: TCP SYN-Sweep (viele SYN in kurzer Zeit)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: TCP SYN-Sweep (viele SYN in kurzer Zeit)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -sS -p1-100 &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;&amp;lt;ZIEL&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -sS -p1-100 &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (msg:&amp;quot;OWN SCAN TCP SYN sweep&amp;quot;; flow:stateless,to_server; flags:S; detection_filter:track by_src,count 20,seconds 5; classtype:attempted-recon; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;60&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any (msg:&amp;quot;OWN SCAN TCP SYN sweep&amp;quot;; flow:stateless,to_server; flags:S; detection_filter:track by_src,count 20,seconds 5; classtype:attempted-recon; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000060&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;TCP NULL&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Scan (keine Flags gesetzt)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;UDP&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Sweep mit leerer Payload&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;sN &lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p1&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;100 &amp;lt;ZIEL&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sU &lt;/ins&gt;--&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;min-rate=1000 10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;tcp $EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (msg:&amp;quot;OWN SCAN &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;TCP NULL scan&lt;/del&gt;&amp;quot;; flow:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;stateless,&lt;/del&gt;to_server; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;flags&lt;/del&gt;:0; detection_filter:track by_src,count &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;5&lt;/del&gt;,seconds 10; classtype:attempted-recon; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;61&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;udp any &lt;/ins&gt;any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any (msg:&amp;quot;OWN SCAN &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;UDP sweep (empty probes)&lt;/ins&gt;&amp;quot;; flow:to_server; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;dsize&lt;/ins&gt;:0; detection_filter:track by_src,count &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;15&lt;/ins&gt;,seconds 10; classtype:attempted-recon; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000064&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;TCP FIN&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Scan &lt;/del&gt;(&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;nur FIN&lt;/del&gt;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Scan: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ICMP Ping&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Sweep &lt;/ins&gt;(&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;viele Echo-Requests&lt;/ins&gt;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;sF -p1-100 &amp;lt;ZIEL&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: nmap -&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sn 10.88.2XX.0/24&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;tcp $EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (msg:&amp;quot;OWN SCAN &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;TCP FIN scan&lt;/del&gt;&amp;quot;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;flow:stateless,to_server; flags&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;F&lt;/del&gt;; detection_filter:track by_src,count &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;5&lt;/del&gt;,seconds &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/del&gt;; classtype:attempted-recon; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;62&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;icmp any &lt;/ins&gt;any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any (msg:&amp;quot;OWN SCAN &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ICMP ping sweep&lt;/ins&gt;&amp;quot;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;itype&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;8&lt;/ins&gt;; detection_filter:track by_src,count &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/ins&gt;,seconds &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;5&lt;/ins&gt;; classtype:attempted-recon; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000065&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Scan: TCP XMAS-Scan (FIN+PSH+URG)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Brute Force SSH&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;nmap &lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;sX &lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;p1-100 &amp;lt;ZIEL&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;hydra &lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;l root &lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;P /usr/share/wordlists/rockyou.txt ssh://10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (msg:&amp;quot;OWN &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;SCAN TCP XMAS scan&lt;/del&gt;&amp;quot;; flow:stateless&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;,to_server&lt;/del&gt;; flags:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;FPU&lt;/del&gt;; detection_filter:track by_src,count &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;5&lt;/del&gt;,seconds &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/del&gt;; classtype:attempted-recon; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;63&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any -&amp;gt; any &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;22 &lt;/ins&gt;(msg:&amp;quot;OWN &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;SSH Brute Force&lt;/ins&gt;&amp;quot;; flow:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;to_server,&lt;/ins&gt;stateless; flags:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;S&lt;/ins&gt;; detection_filter:track by_src,count &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;10&lt;/ins&gt;,seconds &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;60&lt;/ins&gt;; classtype:attempted-recon; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000066&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Scan&lt;/del&gt;: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;UDP&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Sweep mit leerer Payload&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;HTTP&lt;/ins&gt;: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sqlmap User&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Agent erkennen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;nmap &lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;sU &lt;/del&gt;--&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;min&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;rate&lt;/del&gt;=&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;1000 &amp;lt;ZIEL&amp;gt;&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;sqlmap &lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;u &amp;quot;http://www.it2XX.int/sql&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;classic.php&amp;quot; &lt;/ins&gt;--&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;data &amp;quot;username&lt;/ins&gt;=&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;test&amp;quot;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;drop udp $EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET 1:65535 &lt;/del&gt;(msg:&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;OWN SCAN UDP sweep (empty probes)&lt;/del&gt;&amp;quot;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;flow:to_server&lt;/del&gt;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;dsize&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;0&lt;/del&gt;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;detection_filter:track by_src,count 15,seconds 10&lt;/del&gt;; classtype:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;attempted&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;recon&lt;/del&gt;; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;64&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;alert http any &lt;/ins&gt;any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any any &lt;/ins&gt;(msg:&amp;quot;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;SQLmap Scanner detected&lt;/ins&gt;&amp;quot;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;http.user_agent&lt;/ins&gt;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;content&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;quot;sqlmap&amp;quot;&lt;/ins&gt;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;nocase&lt;/ins&gt;; classtype:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;web-application&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;attack&lt;/ins&gt;; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000070&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Scan&lt;/del&gt;: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;ICMP Ping&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Sweep (viele Echo-Requests)&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;HTTP&lt;/ins&gt;: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;curl User&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Agent erkennen&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;nmap -sn &amp;lt;NETZ&amp;gt;&lt;/del&gt;/&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;24&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Test: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;curl http://www.it2XX.int&lt;/ins&gt;/&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;host.php&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;drop icmp $EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (msg:&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;OWN SCAN ICMP ping sweep&lt;/del&gt;&amp;quot;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;itype&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;8&lt;/del&gt;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;detection_filter:track by_src,count 10,seconds 5&lt;/del&gt;; classtype:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;attempted&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;recon&lt;/del&gt;; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;65&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;alert http any &lt;/ins&gt;any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any (msg:&amp;quot;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;curl User-Agent detected&lt;/ins&gt;&amp;quot;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;http.user_agent; content&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;quot;curl&amp;quot;&lt;/ins&gt;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;nocase&lt;/ins&gt;; classtype:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;policy&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;violation&lt;/ins&gt;; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000071&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Aktion&lt;/del&gt;: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;?&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ICMP Tunnel - großes Payload&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;drop tcp $EXTERNAL_NET &lt;/del&gt;any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET 22 &lt;/del&gt;(msg:&amp;quot;OWN &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;SCAN SSH Brute Force&lt;/del&gt;&amp;quot;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;flow&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;to_server,stateless&lt;/del&gt;; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;flags&lt;/del&gt;:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;S; detection_filter:track by_src,count 10,seconds 60&lt;/del&gt;; classtype:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;attempted&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;recon&lt;/del&gt;; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;66&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Test&lt;/ins&gt;: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ping -c 5 -s 500 10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;alert icmp any &lt;/ins&gt;any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any any &lt;/ins&gt;(msg:&amp;quot;OWN &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;ICMP Large Payload - possible tunnel&lt;/ins&gt;&amp;quot;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;itype&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;8&lt;/ins&gt;; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;dsize&lt;/ins&gt;:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;&amp;gt;200&lt;/ins&gt;; classtype:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;misc&lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;attack&lt;/ins&gt;; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000072&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;--- &lt;/del&gt;TCP SYN Flood &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;(Sehr häufiger DDos&lt;/del&gt;-&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Typ) &lt;/del&gt;---&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# TCP SYN Flood&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert tcp any any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;flags:S; &lt;/del&gt;msg:&amp;quot;TCP SYN Flood Potential Detected&amp;quot;; threshold: type both, track by_dst, count 150, seconds 10; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;1000003&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Test: hping3 -S &lt;/ins&gt;--&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;flood &lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;V &lt;/ins&gt;-&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;p 80 10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert tcp any any -&amp;gt; &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;any &lt;/ins&gt;any (msg:&amp;quot;TCP SYN Flood Potential Detected&amp;quot;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;; flags:S&lt;/ins&gt;; threshold: type both, track by_dst, count 150, seconds 10&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;; classtype:misc-attack&lt;/ins&gt;; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000073&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;--- (Optional) Einfacher &amp;quot;Hello World&amp;quot; Treffer für Tests ---&lt;/del&gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;SSH Connection Attempt&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert tcp any any -&amp;gt; &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;$HOME_NET &lt;/del&gt;any (msg:&amp;quot;&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;TEST - &lt;/del&gt;SSH Connection Attempt&amp;quot;; content:&amp;quot;SSH&amp;quot;; nocase; sid:&lt;del class=&quot;diffchange diffchange-inline&quot;&gt;1000006&lt;/del&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;# Test: ssh root@10.88.2XX.21&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;alert tcp any any -&amp;gt; any &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;22 &lt;/ins&gt;(msg:&amp;quot;SSH Connection Attempt&amp;quot;; content:&amp;quot;SSH&amp;quot;; nocase&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;; classtype:misc-activity&lt;/ins&gt;; sid:&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;9000074&lt;/ins&gt;; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;

&lt;!-- diff cache key my_wiki:diff::1.12:old-69257:rev-69258 --&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69257&amp;oldid=prev</id>
		<title>Thomas.will am 30. April 2026 um 10:33 Uhr</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69257&amp;oldid=prev"/>
		<updated>2026-04-30T10:33:01Z</updated>

		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class=&quot;diff diff-contentalign-left diff-editfont-monospace&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;de&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Nächstältere Version&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Version vom 30. April 2026, 10:33 Uhr&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l46&quot; &gt;Zeile 46:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Zeile 46:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Aktion: ?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;# Aktion: ?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET 22 (msg:&amp;quot;OWN SCAN SSH Brute Force&amp;quot;; flow:to_server,stateless; flags:S; detection_filter:track by_src,count 10,seconds 60; classtype:attempted-recon; sid:66; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET 22 (msg:&amp;quot;OWN SCAN SSH Brute Force&amp;quot;; flow:to_server,stateless; flags:S; detection_filter:track by_src,count 10,seconds 60; classtype:attempted-recon; sid:66; rev:1;)&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# --- TCP SYN Flood (Sehr häufiger DDos-Typ) ---&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;alert tcp any any -&amp;gt; $HOME_NET any (flags:S; msg:&amp;quot;TCP SYN Flood Potential Detected&amp;quot;; threshold: type both, track by_dst, count 150, seconds 10; sid:1000003; rev:1;)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;# --- (Optional) Einfacher &amp;quot;Hello World&amp;quot; Treffer für Tests ---&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt; &lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;alert tcp any any -&amp;gt; $HOME_NET any (msg:&amp;quot;TEST - SSH Connection Attempt&amp;quot;; content:&amp;quot;SSH&amp;quot;; nocase; sid:1000006; rev:1;)&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;lt;/pre&amp;gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
	<entry>
		<id>https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69254&amp;oldid=prev</id>
		<title>Thomas.will: Die Seite wurde neu angelegt: „&lt;pre&gt; # ICMP: einfacher Ping/Traceroute (schneller Funktionstest) # Test: ping -c1 &lt;ZIEL&gt; alert icmp any any -&gt; any any (msg:&quot;ICMP Test&quot;; classtype:misc-activi…“</title>
		<link rel="alternate" type="text/html" href="https://wiki.ixheim.de/index.php?title=Vorlage:Suricata-rules&amp;diff=69254&amp;oldid=prev"/>
		<updated>2026-04-30T10:28:28Z</updated>

		<summary type="html">&lt;p&gt;Die Seite wurde neu angelegt: „&amp;lt;pre&amp;gt; # ICMP: einfacher Ping/Traceroute (schneller Funktionstest) # Test: ping -c1 &amp;lt;ZIEL&amp;gt; alert icmp any any -&amp;gt; any any (msg:&amp;quot;ICMP Test&amp;quot;; classtype:misc-activi…“&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Neue Seite&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;pre&amp;gt;&lt;br /&gt;
# ICMP: einfacher Ping/Traceroute (schneller Funktionstest)&lt;br /&gt;
# Test: ping -c1 &amp;lt;ZIEL&amp;gt;&lt;br /&gt;
alert icmp any any -&amp;gt; any any (msg:&amp;quot;ICMP Test&amp;quot;; classtype:misc-activity; sid:41;)&lt;br /&gt;
&lt;br /&gt;
# HTTP: mögliches Command-Injection-Merkmal (Semikolon) in POST-Body&lt;br /&gt;
# Test: curl -X POST http://&amp;lt;ZIEL&amp;gt;/ -d &amp;quot;q=test%3Bls&amp;quot;&lt;br /&gt;
alert http any any -&amp;gt; any any (msg:&amp;quot;Command Injection - Semicolon in POST DATA&amp;quot;; classtype:web-application-attack; flow:established; content:&amp;quot;%3B&amp;quot;; nocase; http_client_body; sid:2;)&lt;br /&gt;
&lt;br /&gt;
# HTTP: mögliches SQLi-Merkmal (einfaches Hochkomma) in POST-Body&lt;br /&gt;
# Test: curl -X POST http://&amp;lt;ZIEL&amp;gt;/login -d &amp;quot;u=a&amp;amp;p='%20OR%201=1&amp;quot;&lt;br /&gt;
alert http any any -&amp;gt; any any (msg:&amp;quot;Possible SQL Injection (singlequote in POST)&amp;quot;; classtype:web-application-attack; flow:established,to_server; content:&amp;quot;%27&amp;quot;; nocase; http_client_body; sid:3;)&lt;br /&gt;
&lt;br /&gt;
# DNS: Policy – verbietet &amp;quot;google&amp;quot; in DNS-Queries&lt;br /&gt;
# Test: dig google.com @&amp;lt;FW&amp;gt;&lt;br /&gt;
drop dns any any -&amp;gt; any any (msg:&amp;quot;Kein Googlen&amp;quot;; dns.query; content:&amp;quot;google&amp;quot;; nocase; classtype:policy-violation; sid:43;)&lt;br /&gt;
&lt;br /&gt;
# DoS: viele identische kurze HTTP-GETs (LOIC-ähnlich)&lt;br /&gt;
# Test: ab -n 1000 -c 500 http://&amp;lt;ZIEL&amp;gt;/&lt;br /&gt;
drop tcp any any -&amp;gt; any any (msg:&amp;quot;ET DOS Terse HTTP GET Likely LOIC&amp;quot;; flow:to_server,established; dsize:18; content:&amp;quot;GET / HTTP/1.1|0d 0a 0d 0a|&amp;quot;; depth:18; threshold:type both,track by_dst,count 500,seconds 60; classtype:own-dos; sid:54; rev:2; metadata:created_at 2014_10_03, confidence Medium, signature_severity Major, updated_at 2019_07_26;)&lt;br /&gt;
&lt;br /&gt;
# Scan: TCP SYN-Sweep (viele SYN in kurzer Zeit)&lt;br /&gt;
# Test: nmap -sS -p1-100 &amp;lt;ZIEL&amp;gt;&lt;br /&gt;
drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET any (msg:&amp;quot;OWN SCAN TCP SYN sweep&amp;quot;; flow:stateless,to_server; flags:S; detection_filter:track by_src,count 20,seconds 5; classtype:attempted-recon; sid:60; rev:1;)&lt;br /&gt;
&lt;br /&gt;
# Scan: TCP NULL-Scan (keine Flags gesetzt)&lt;br /&gt;
# Test: nmap -sN -p1-100 &amp;lt;ZIEL&amp;gt;&lt;br /&gt;
drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET any (msg:&amp;quot;OWN SCAN TCP NULL scan&amp;quot;; flow:stateless,to_server; flags:0; detection_filter:track by_src,count 5,seconds 10; classtype:attempted-recon; sid:61; rev:1;)&lt;br /&gt;
&lt;br /&gt;
# Scan: TCP FIN-Scan (nur FIN)&lt;br /&gt;
# Test: nmap -sF -p1-100 &amp;lt;ZIEL&amp;gt;&lt;br /&gt;
drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET any (msg:&amp;quot;OWN SCAN TCP FIN scan&amp;quot;; flow:stateless,to_server; flags:F; detection_filter:track by_src,count 5,seconds 10; classtype:attempted-recon; sid:62; rev:1;)&lt;br /&gt;
&lt;br /&gt;
# Scan: TCP XMAS-Scan (FIN+PSH+URG)&lt;br /&gt;
# Test: nmap -sX -p1-100 &amp;lt;ZIEL&amp;gt;&lt;br /&gt;
drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET any (msg:&amp;quot;OWN SCAN TCP XMAS scan&amp;quot;; flow:stateless,to_server; flags:FPU; detection_filter:track by_src,count 5,seconds 10; classtype:attempted-recon; sid:63; rev:1;)&lt;br /&gt;
&lt;br /&gt;
# Scan: UDP-Sweep mit leerer Payload&lt;br /&gt;
# Test: nmap -sU --min-rate=1000 &amp;lt;ZIEL&amp;gt;&lt;br /&gt;
drop udp $EXTERNAL_NET any -&amp;gt; $HOME_NET 1:65535 (msg:&amp;quot;OWN SCAN UDP sweep (empty probes)&amp;quot;; flow:to_server; dsize:0; detection_filter:track by_src,count 15,seconds 10; classtype:attempted-recon; sid:64; rev:1;)&lt;br /&gt;
&lt;br /&gt;
# Scan: ICMP Ping-Sweep (viele Echo-Requests)&lt;br /&gt;
# Test: nmap -sn &amp;lt;NETZ&amp;gt;/24&lt;br /&gt;
drop icmp $EXTERNAL_NET any -&amp;gt; $HOME_NET any (msg:&amp;quot;OWN SCAN ICMP ping sweep&amp;quot;; itype:8; detection_filter:track by_src,count 10,seconds 5; classtype:attempted-recon; sid:65; rev:1;)&lt;br /&gt;
&lt;br /&gt;
# Aktion: ?&lt;br /&gt;
drop tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET 22 (msg:&amp;quot;OWN SCAN SSH Brute Force&amp;quot;; flow:to_server,stateless; flags:S; detection_filter:track by_src,count 10,seconds 60; classtype:attempted-recon; sid:66; rev:1;)&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Thomas.will</name></author>
	</entry>
</feed>