Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66666
This rule looks for a JSON field named "clientip" containing characters commonly used in SQL injection payloads within Zabbix protocol messages. Successful exploitation could allow an attacker to execute arbitrary SQL commands on the Zabbix backend database.
1:66665
This rule looks for a set of JavaScript instructions that are specific and intended to exploit an out-of-bounds vulnerability in the V8 engine of Google Chromium.
1:66664
This rule looks for a set of JavaScript instructions that are specific and intended to exploit an out-of-bounds vulnerability in the V8 engine of Google Chromium.
1:66663
This rule looks for a Redis protocol request that includes a "COMMAND" "GETKEYS" (or "GETKEYSANDFLAGS") followed by a "ZUNIONSTORE" command within a large payload. Successful exploitation may lead to heap memory corruption and remote code execution on the targeted Redis instance.
1:66662
This rule looks for server responses containing malicious javascript that leverages a type confusion to achieve arbitrary read/write of Chromium-based browser memory space.
1:66660
This rule looks for HTTP POST requests to a LiteLLM test endpoint where the Host header contains special characters that can be used to bypass authentication. Successful exploitation may allow an attacker to execute arbitrary commands on the server and bypass access controls.