Rule Category

SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.

Alert Message

SERVER-WEBAPP IBM Data Risk Manager directory traversal attempt

Rule Explanation

The rule looks for HTTP traffic to `/albatross/eurekaservice/fetchLogFiles` endpoint with `logFileNameList` JSON key with value that has directory traversal attempt.

What To Look For

The rule is triggered when attacker attempts to download file using directory traversal over HTTP with `/albatross/eurekaservice/fetchLogFiles` endpoint

Known Usage

Public information/Proof of Concept available

False Positives

No known false positives


Cisco Talos Intelligence Group

MITRE ATT&CK Framework

Tactic: Exfiltration

Technique: Exfiltration Over Alternative Protocol

