r1 - 06 Oct 2009 - 18:19:03 - TWikiGuestYou are here: TWiki >  Main Web > 2009484

alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB_SERVER Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; nocase; content:"../"; depth:200; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Cpanel; sid:2009484; rev:6;)

Added 2009-10-06 14:19:03 UTC

 


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB_SERVER Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; nocase; content:"../"; depth:200; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Cpanel; sid:2009484; rev:6;)

Added 2009-10-06 14:19:03 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; nocase; content:"../"; depth:200; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB/WEB_Cpanel; sid:2009484; rev:4;)

Added 2009-07-02 11:15:34 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; nocase; content:"../"; depth:200; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB/WEB_Cpanel; sid:2009484; rev:4;)

Added 2009-07-02 11:15:34 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; nocase; pcre:"/domain\s*=\s*(\.\.\/){1,}/Ui"; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB/WEB_Cpanel; sid:2009484; rev:3;)

Added 2009-07-01 21:30:34 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; nocase; pcre:"/domain\s*=\s*(\.\.\/){1,}/Ui"; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB/WEB_Cpanel; sid:2009484; rev:3;)

Added 2009-07-01 21:30:34 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; pcre:"/domain\s*=\s*(\.\.\/){1,}/Ui"; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB/WEB_Cpanel; sid:2009484; rev:2;)

Added 2009-07-01 20:03:01 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; pcre:"/domain\s*=\s*(\.\.\/){1,}/Ui"; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2009484; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB/WEB_Cpanel; sid:2009484; rev:2;)

Added 2009-07-01 20:03:01 UTC


alert tcp $EXTERNAL_NET any -> $HOME_NET $HTTP_PORTS (msg:"ET WEB Cpanel lastvisit.html Arbitary file disclosure"; flow:to_server,established; content:"GET "; depth:4; uricontent:"lastvist.html?"; nocase; uricontent:"domain="; pcre:"/domain\s*=\s*(\.\.\/){1,}/Ui"; reference:url,milw0rm.com/exploits/9039; reference:bugtraq,35518; classtype:web-application-attack; sid:2009484; rev:1;)

Added 2009-07-01 10:45:35 UTC


Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback