[Snort-sigs] Low hanging fruit #2
jlay at ...3266...
Thu Sep 13 12:01:48 EDT 2012
On 2012-09-13 09:55, Joel Esler wrote:
> Thanks James, taking a look.
> On Sep 12, 2012, at 5:58 PM, James Lay <jlay at ...3266...>
>> Yea...that was a good read on the Apache Mod issue:
>> alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any
>> (msg:"INDICATOR-COMPROMISE Page with YWZmaWQ9MDUyODg";
>> established; file_data; content:"YWZmaWQ9MDUyODg"; metadata:policy
>> balanced-ips drop, policy security-ips drop, service http;
>> classtype:bad-unknown; sid:10000026;
>> Certain this rule will be exciting until they change their ways.
>> Hopefully I've got the flow right..don't have a pcap to bounce it
Looks like I jumped the gun as sigs 2015649 and 2015698 on the ET side
have this. I'll check ALL the rulesets from now on to make sure I'm not
wasting anyone's time. Happy Thursday :)
More information about the Snort-sigs