This is a false positive attack based on the content of my yesterday's diary regarding based BSOD phone scam. The fact that the page contains sample of HTML code seems to trigger your IDS rule.
the site administrator is informed, awaiting reply. The today diary of dshield.org is shown without any blocking, so I guess it was the code on the yesterday diary, being misinterpreted as an attack.
Please contact an admin to request access.