backdoor.rules

来自「IPv4和IPv6下发任意包的程序」· RULES 代码 · 共 8 行

RULES
8
字号
var HOME_NET anyvar EXTERNAL_NET anylert tcp $EXTERNAL_NET 27374 -> $HOME_NET any (msg: "BACKDOOR SIG - SubSseven 22"; flags: A+; content: "|0d0a5b52504c5d3030320d0a|"; reference:arachnids,485;)alert tcp $EXTERNAL_NET 1024: -> $HOME_NET 2589 (msg: "BACKDOOR - Dagger_1.4.0_client_connect"; flags: A+; content: "|0b 00 00 00 07 00 00 00|Connect"; depth: 16; reference:arachnids,483;)alert tcp $HOME_NET 2589 -> $EXTERNAL_NET 1024: (msg: "BACKDOOR - Dagger_1.4.0"; flags: A+; content: "|3200000006000000|Drives|2400|"; depth: 16; reference:arachnids,484;)

⌨️ 快捷键说明

复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?