Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66671
This rule looks for a specific IKEv1 authentication sequence that includes a known magic identifier followed by a byte pattern indicating the vulnerable flag. Successful exploitation allows an unauthenticated client to gain access to the VPN service.
1:66670
This rule looks for a specific IKEv1 authentication sequence that includes a known magic identifier followed by a byte pattern indicating the vulnerable flag. Successful exploitation allows an unauthenticated client to gain access to the VPN service.
1:66669
This rule looks for HTTP requests that contain a CacheWarmer cookie with a marker followed by base64-encoded data indicative of a serialized PHP object. Successful exploitation can lead to remote code execution on the targeted Magento server.
1:66668
This rule looks for bytes known to be specific to files that are intended to exploit a remote code execution vulnerability in Windows NTFS.
1:66667
This rule looks for bytes known to be specific to files that are intended to exploit a remote code execution vulnerability in Windows NTFS.
1:66666
This rule looks for a JSON field named "clientip" containing characters commonly used in SQL injection payloads within Zabbix protocol messages. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the Zabbix backend database.