[Snort-sigs] SID 18773

vincent at ...3611... vincent at ...3611...
Thu Jan 12 09:34:10 EST 2012

What ex​actly is Snort SID 18773 attempting to alert on?  The rule name is 'BLACKLIST URI for known malicious URI - /stat.htm" and contains some very specific content clauses.  When I follow the URL specified by one of these alerts, it points to a 1x1 pixel GIF image.  Is this part of a known exploit?


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20120112/0fda1193/attachment.html>

More information about the Snort-sigs mailing list