[Snort-sigs] add new simple rule for detect "Jboss % attempt"

rmkml rmkml at ...324...
Mon Aug 29 13:10:06 EDT 2005


Hi,

Please check and (maybe) add rule :

web-misc.rules:alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 8083 
(msg:"WEB-MISC Jboss % attempt"; flow:to_server,established; content:"GET 
%"; reference:bugtraq,13985; reference:cve,2005-2006; reference:osvdb,17403; 
classtype:attempted-recon;)

Regards
Rmkml




More information about the Snort-sigs mailing list