[Snort-sigs] Nginx default landing page sig

James Lay jlay at ...3266...
Fri Dec 16 17:25:45 EST 2016


After wgetting adups page instead of POSTing 
(http://blog.trustlook.com/2016/12/12/digging-into-adups-fota-data-collection-details/) 
and seeing the default, I figure this might catch lazy malicious actors.

alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"INFO 
Unconfigured nginx access"; flow:from_server,established; content:"200"; 
http_stat_code; content:"|3C|title|3E|Welcome to 
nginx|213C2F|title|3E|"; http_client_body; classtype:bad-unknown; 
sid:10000243; rev:1;)

Sanity tested only.

James




More information about the Snort-sigs mailing list