Talos Rules 2022-06-02
This release adds and modifies rules in several categories.

Talos has added and modified multiple rules in the and server-webapp rule sets to provide coverage for emerging threats from these technologies.

For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.

Change logs

2022-06-02 21:51:13 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091900.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:13 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091801.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:13 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091701.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:13 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091700.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:13 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091601.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)

Modified Rules:


 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091600.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091501.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091401.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091300.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2091101.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59910 <-> ENABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (snort3-server-webapp.rules)
 * 1:59913 <-> ENABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (snort3-server-webapp.rules)
 * 1:59922 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (snort3-server-webapp.rules)
 * 1:59914 <-> ENABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (snort3-server-webapp.rules)
 * 1:59918 <-> ENABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (snort3-server-webapp.rules)
 * 1:59912 <-> ENABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (snort3-server-webapp.rules)
 * 1:59923 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (snort3-server-webapp.rules)
 * 1:59924 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (snort3-server-webapp.rules)
 * 1:59911 <-> ENABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (snort3-server-webapp.rules)
 * 1:59916 <-> ENABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (snort3-server-webapp.rules)
 * 1:59917 <-> ENABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (snort3-server-webapp.rules)
 * 1:59915 <-> ENABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (snort3-server-webapp.rules)
 * 1:59908 <-> ENABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (snort3-server-webapp.rules)
 * 1:59907 <-> ENABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (snort3-server-webapp.rules)
 * 1:59909 <-> ENABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (snort3-server-webapp.rules)
 * 1:59921 <-> ENABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (snort3-server-webapp.rules)

Modified Rules:



2022-06-02 21:51:14 UTC

Snort Subscriber Rules Update

Date: 2022-06-02

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 2983.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:59920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt (os-windows.rules)
 * 1:59923 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59913 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59924 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59922 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)
 * 1:59915 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59906 <-> DISABLED <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt (server-webapp.rules)
 * 1:59907 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59908 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59909 <-> DISABLED <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt (server-webapp.rules)
 * 1:59910 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59917 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59914 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59911 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59918 <-> DISABLED <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt (server-webapp.rules)
 * 1:59912 <-> DISABLED <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt (server-webapp.rules)
 * 1:59916 <-> DISABLED <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt (server-webapp.rules)
 * 1:59921 <-> DISABLED <-> SERVER-WEBAPP Netgear R8500 command injection attempt (server-webapp.rules)

Modified Rules:


 * 1:59889 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)
 * 1:59890 <-> DISABLED <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt (os-windows.rules)

2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.0.3.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.0.3.4.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.0.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.1.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.3.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.4.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.5.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:45 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.7.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:46 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.9.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:46 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.11.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:46 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.15.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:46 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.18.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:46 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.20.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt


2022-06-02 21:53:46 UTC

Snort Subscriber Rules Update

Date: 2022-06-02-001

This is the complete list of rules modified and added in the Sourcefire VRT Certified rule pack for Snort version 3.1.21.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:300196 <-> OS-WINDOWS Microsoft Windows search-ms protocol invocation attempt
* 1:59906 <-> SERVER-WEBAPP Apache Struts OGNL sandbox bypass attempt
* 1:59907 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59908 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59909 <-> SERVER-WEBAPP Eaton Intelligent Power Manager directory traversal attempt
* 1:59910 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59911 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59912 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59913 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59914 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59915 <-> SERVER-WEBAPP SonicWall Secure Remote Access SQL injection attempt
* 1:59916 <-> SERVER-WEBAPP Netgear ProSAFE switch debug command execution attempt
* 1:59917 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59918 <-> SERVER-WEBAPP QNAP NAS Surveillance Station plugin buffer overflow attempt
* 1:59921 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59922 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59923 <-> SERVER-WEBAPP Netgear R8500 command injection attempt
* 1:59924 <-> SERVER-WEBAPP Netgear R8500 command injection attempt

Modified Rules:

* 1:300192 <-> OS-WINDOWS Microsoft Support Diagnostic Tool ms-msdt protocol use attempt