Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:67009
This rule triggers on an obfuscated javascript payload that is used for a phishing attack. It specifically is looking for the XOR decryption loop used commonly by ClickFix to obfuscate malacious intent.
1:67008
This rule triggers on an obfuscated javascript payload that is used for a phishing attack. It specifically is looking for the XOR decryption loop used commonly by ClickFix to obfuscate malacious intent.
1:67007
This rule looks for HTTP requests that target webshells dropped into Netscaler appliances under the "vpn/theme/" URI. Successful exploitation can lead to unauthorized execution of malicious scripts via the planted webshell.
1:67004
This rule looks for an InfoRail protocol header that includes a payform indicator and a distlist indicator, followed by a payload composed solely of space characters. Successful exploitation results in the service crashing, leading to a denial-of-service condition.
1:67003
This rule looks for HTTP requests to the "/accessv2" endpoint that include the JSON key "apiuser" with a value containing a sequence of four or more single‑quote characters. Successful exploitation may allow an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance.
1:67002
This rule looks for multiple HTTP requests to the Gitea diffpatch API endpoint that attempt to write an executable Git hook. Successful exploitation allows an attacker to write a malicious hook script that can be executed by the server, leading to remote code execution.