Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66618
This rule looks for Java RMI return data that contains identifiers associated with a remote invocation handler and unicast reference objects. Successful exploitation could allow an attacker to execute arbitrary commands on the UPS device.
1:66617
This rule looks for JavaScript code that is known to exploit a sandbox escape vulnerability in VM2, allowing for arbitrary remote code execution.
1:66616
This rule looks for JavaScript code that is known to exploit a sandbox escape vulnerability in VM2, allowing for arbitrary remote code execution.
1:66615
This rule looks for JavaScript code that is known to exploit a sandbox escape vulnerability in VM2, allowing for arbitrary remote code execution.
1:66613
This rule looks for HTTP requests that contain a distinctive GitHub search URI used by the Nx Console post‑compromise downloader. Successful exploitation indicates the host is contacting a command‑and‑control endpoint to retrieve further malicious code.
1:56551
This rule looks for JSON payloads sent to the "/service/" path with a "createUser" request that contain command injection characters within the "username" or "password" fields. Successful exploitation could allow an attacker to execute arbitrary operating system commands on the controller.