[Snort-sigs] JBoss /web-console sig

Jon Hart jhart at ...288...
Fri Jun 2 19:27:43 EDT 2006


Very similar to the other JBoss uricontent sig I sent.  /web-console on
an exposed JBoss server gives up a bunch of config information, as well
as fires up a Java app to get a tree view of the exposed beans.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"JBoss
web-console access"; flow:to_server,established;
uricontent:"/web-console"; sid:12345679; rev:1;)

-jon




More information about the Snort-sigs mailing list