Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66967
This rule looks for HTTP requests to the "/wsproxy" endpoint that contain a bmID parameter beginning with a dash-prefixed value and a User-Agent header identifying the "SMA Connect Agent". Successful exploitation allows an attacker to tunnel arbitrary TCP traffic to internal services behind the firewall.
1:66966
This rule looks for specific malicious SQL injection sequences present in HTTP batch requests sent to WordPress web applications.
1:66965
This rule looks for specific malicious SQL injection sequences present in HTTP batch requests sent to WordPress web applications.
1:66964
This rule looks for path traversal sequences present in the following parameters in HTTP requests sent to the /rollbackConfirm.action endpoint on SonicWall SMA1000 Appliances web applications: hotfix.
1:66963
This rule looks for path traversal sequences present in the following parameters in HTTP requests sent to the /rollbackConfirm.action endpoint on SonicWall SMA1000 Appliances web applications: hotfix.
1:66962
This rule looks for path traversal sequences present in the following parameters in HTTP requests sent to the /rollbackConfirm.action endpoint on SonicWall SMA1000 Appliances web applications: hotfix.