[Snort-sigs] bad rule

Gentoo-Wally gentoowally at ...2420...
Fri Jul 28 14:55:27 EDT 2006


Just updated my community set and the following rule has a syntax error...

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS
(msg:"COMMUNITY WEB-PHP Horde index.php show XSS attempt";
flow:established,to_server; uricontent:"/services/help/index.php";
nocase:; uricontent:"show="; nocase:; uricontent:"URL=javascript";
nocase:; reference:bugtraq,18845; classtype:web-application-attack;
sid:100000703; rev:1;)

Should be....

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS
(msg:"COMMUNITY WEB-PHP Horde index.php show XSS attempt";
flow:established,to_server; uricontent:"/services/help/index.php";
nocase; uricontent:"show="; nocase; uricontent:"URL=javascript";
nocase; reference:bugtraq,18845; classtype:web-application-attack;
sid:100000703; rev:1;)

changed the three nocase:; to nocase;

wally




More information about the Snort-sigs mailing list