Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66644
This rule looks for bytes known to be specific to files that are intended to exploit an elevation of privilege vulnerability in the Microsoft Windows operating system.
1:66642
This rule looks for HTTP requests to Drupal JSON:API endpoints where the query string contains a "filter" parameter with characters commonly used in SQL injection. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the backend database.
1:66639
This rule looks for the PHP file magic ("<?") included in the client body of HTTP requests sent to the /wordpress/wp-content/plugins/wp-time-capsule/wp-tcapsule-bridge/upload/php/index.php endpoint on WordPress WP Time Capsule web applications.
1:66638
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /wordpress/wp-admin/admin-ajax.php endpoint on WordPress Backup Migration web applications: url.
1:66637
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /wordpress/wp-admin/admin-ajax.php endpoint on WordPress Backup Migration web applications: url.
1:66636
This rule looks for command injection metacharacters present in the following parameters in HTTP requests sent to the /wordpress/wp-admin/admin-ajax.php endpoint on WordPress Backup Migration web applications: url.