[Snort-sigs] Web service rules

Joel Maslak jmaslak at ...1560...
Fri Jun 6 05:16:18 EDT 2003


Oops - I made a typo in one of these rules.  Here's what the Trace rule 
should really look like (I used "trace.asd" when I should have wrote 
"trace.axd"):

> alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-IIS 
ASP.NET Trace attempt"; flow:to_server,established; 
uricontent:"trace.axd"; nocase; classtype:web-application-attack; 
sid:1000003; rev:1;)

-- 
Joel Maslak
Antelope Enterprises





More information about the Snort-sigs mailing list