Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:67157
This rule looks for remote code execution strings present in HTTP requests sent to a vulnerable endpoint on Next.js web applications.
1:67156
This rule looks for a malformed RPCSEC_GSS authentication packet sent to a vulnerable FreeBSD system.
1:67155
This rule looks for a malformed RPCSEC_GSS authentication packet sent to a vulnerable FreeBSD system.
1:67154
This rule looks for a "RETR" command at the start of an FTP request and a second command appearing after a CRLF sequence within the same packet. Successful exploitation allows an attacker to bypass file permissions and gain elevated access on the FTP server.
1:67153
This rule looks for multipart HTTP requests to the remoteControlAction.do endpoint that contain a Java BeanUtils property traversal assigning the Jetty CGI servlet class to a servlet holder. Successful exploitation allows an unauthenticated attacker to execute arbitrary commands on the target server.
1:65229
This rule searches for server responses with authorization endpoint attributes containing attempts to execute arbitrary commands on the MCP-Remote client.