Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66873
This rule looks for authentication bypass sequences present in the URI path part in HTTP requests sent to the /oidc endpoint on SimpleHelp web applications.
1:66872
This rule triggers when a malicious string belonging to the Djinn stealer has been seen in the network
1:66871
This rule looks for malicious attempts to exploit an authentication bypass vulnerability within Apache ShenYu web applications
1:66870
This rule looks for a poisoned response of Apache Dubbo applications via a maliciously crafted script route rule
1:66869
This rule looks for HTTP requests to the OFBiz SOAPService endpoint that contain an XML payload with a custom object tag and a serialized payload marker. Successful exploitation may allow an attacker to execute arbitrary code on the server.
1:66868
This rule looks for a series of JavaScript constructs, commonly used in the first-stage of this exploit, appearing in close proximity within HTTP response bodies delivered to a client. Successful exploitation can result in arbitrary code execution on the vulnerable client.