Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:66565
This rule looks for a session cookie that shows indications of being signed with the default secret key.
1:66562
This rule looks for HTTP requests to the "/Demo1/" endpoint that contain the upload command parameter "acmd=Upload" but omit the attachment count parameter "drop-count". Successful exploitation causes the target service to crash, resulting in a denial‑of‑service condition.
1:66561
This rule looks for HTTP requests to the "/Demo1/" endpoint that contain the upload command parameter "acmd=Upload" but omit the attachment count parameter "drop-count". Successful exploitation causes the target service to crash, resulting in a denial‑of‑service condition.
1:66559
This rule looks for JavaScript code that is known to exploit a sandbox escape vulnerability in VM2, allowing for arbitrary remote code execution.
1:66558
This rule looks for JavaScript code that is known to exploit a sandbox escape vulnerability in VM2, allowing for arbitrary remote code execution.
1:66557
This rule looks for JavaScript code that is known to exploit a sandbox escape vulnerability in VM2, allowing for arbitrary remote code execution.