Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:64275
This rule looks for HTTP requests sent to Zoho ManageEngine ServiceDesk Plus web applications that attempt to bypass authentication using specially crafted URI paths.
1:64274
This alerts on buffer overflow attempts in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3
1:64273
This rule specifically looks for known URI endpoints used by the CNC of this malware variant.
1:64271
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /confpremenu.php endpoint on PineApp Mail-SeCure web applications: newkey, confcode, logdir, logname.
1:64270
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /confpremenu.php endpoint on PineApp Mail-SeCure web applications: newkey, confcode, logdir, logname.
1:64269
This rule looks for bytes known to be specific to files that are intended to exploit an elevation of privilege in Veeam Backup and Replication.