Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66679
This rule looks for HTTP requests targeting the endpoint "/system/ws-datachannel-servlet" that include a Java serialization stream header together with identifiers associated with the vulnerable deserialization classes. Successful exploitation can lead to remote code execution on the server.
1:66678
This rule looks for specially crafted Windows Search Protocol CPMCreateQueryIn messages that can lead to a type confusion vulnerability in the Windows Search Protocol service.
1:66677
This rule looks for serialized Java objects containing internal WebLogic class identifiers associated with JNDI references and an LDAP URI in traffic directed to the WebLogic T3 service. Successful exploitation enables the server to perform an outbound LDAP lookup that can lead to remote code execution.
1:66676
This rule looks for HTTP requests targeting the "/mics/api/v2/sentry/mics-config/handleMessage" endpoint that contain a message parameter with the command keyword "execute". Successful exploitation allows an attacker to execute arbitrary operating system commands on the server.
1:66675
This rule looks for HTTP requests targeting the "/mics/api/v2/sentry/mics-config/handleMessage" endpoint that contain a message parameter with the command keyword "execute". Successful exploitation allows an attacker to execute arbitrary operating system commands on the server.
1:66674
This rule looks for SMTP "ETRN" commands that contain characters commonly used in SQL injection payloads. Successful exploitation could allow an attacker to execute arbitrary SQL statements on the mail server's database.