SERVER-WEBAPP -- Snort has detected traffic exploiting vulnerabilities in web based applications on servers.
SERVER-WEBAPP IBM Data Risk Manager directory traversal attempt
The rule looks for HTTP traffic to `/albatross/eurekaservice/fetchLogFiles` endpoint with `logFileNameList` JSON key with value that has directory traversal attempt.
What To Look For
The rule is triggered when attacker attempts to download file using directory traversal over HTTP with `/albatross/eurekaservice/fetchLogFiles` endpoint
Public information/Proof of Concept available
No known false positives
Cisco Talos Intelligence Group