Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66512
This rule looks for a specific sequence of binary instructions associated with the Dirty Frag exploit within file data. Successful exploitation grants root privileges on the affected system.
1:66511
This rule looks for a specific sequence of binary instructions associated with the Dirty Frag exploit within file data. Successful exploitation grants root privileges on the affected system.
1:35170
This rule alerts on specifically crafted traffic that triggers a use after free condition in the MutationObserver function of Microsoft Internet Explorer.
1:66504
This rule looks for XML payloads containing external entity declarations in HTTP requests to the "/geoserver/wfs" endpoint with the "GetMap" operation. Successful exploitation could allow an attacker to read arbitrary files or cause denial of service on the server.
1:66503
This rule looks for traffic to ArgoCD web applications' ServerSideDiff endpoint that contains objects of kind "Secret".
1:66502
This rule looks for specific binary signatures in the HTTP client body that indicate a crafted payload targeting the NGINX rewrite module heap overflow. Successful exploitation allows an attacker to execute arbitrary code on the server.