#alert http $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"HTTP/1.1 404 Not Found|0d 0a|"; depth:24; nocase; content:"<script"; nocase; within:512; metadata: former_category WEB_SERVER; reference:url,doc.emergingthreats.net/2010517; classtype:web-application-attack; sid:2010517; rev:3; metadata:created_at 2010_07_30, updated_at 2017_09_08;)

Added 2017-09-08 16:25:04 UTC


alert http $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"HTTP/1.1 404 Not Found|0d 0a|"; depth:24; nocase; content:"<script"; nocase; within:512; reference:url,doc.emergingthreats.net/2010517; classtype:web-application-attack; sid:2010517; rev:3; metadata:created_at 2010_07_30, updated_at 2010_07_30;)

Added 2017-08-07 21:03:38 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"404"; http_stat_code; content:"Not Found"; nocase; file_data; content:"<script"; nocase; depth:280; reference:url,doc.emergingthreats.net/2010517; classtype:web-application-attack; sid:2010517; rev:6;)

Added 2011-10-12 19:29:56 UTC

this rule gets false positives with accesses from Googlebot (e.g. crawl-66-249-66-16.googlebot.com) so as such it's not usable

-- JohnNaggets - 2016-04-10


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"404"; http_stat_code; content:"Not Found"; nocase; file_data; content:"<script"; nocase; depth:280; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2010517; sid:2010517; rev:6;)

Added 2011-09-14 22:43:09 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"404"; http_stat_code; content:"Not Found"; nocase; file_data; content:"<script"; nocase; depth:280; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2010517; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Error_XSS; sid:2010517; rev:6;)

Added 2011-04-26 18:47:16 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"404"; http_stat_code; content:"Not Found"; nocase; http_stat_msg; file_data; content:"<script"; nocase; depth:280; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2010517; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Error_XSS; sid:2010517; rev:4;)

Added 2011-02-04 17:30:05 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"HTTP/1.1 404 Not Found|0d 0a|"; depth:24; nocase; content:"<script"; nocase; within:512; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2010517; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Error_XSS; sid:2010517; rev:2;)

Added 2009-12-21 10:30:44 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"HTTP/1.1 404 Not Found|0d 0a|"; depth:24; nocase; content:"<script"; nocase; within:512; classtype:web-application-attack; reference:url,doc.emergingthreats.net/2010517; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SERVER/WEB_Error_XSS; sid:2010517; rev:2;)

Added 2009-12-21 10:30:44 UTC


alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 404 XSS Attempt (Local Source)"; flow:from_server,established; content:"HTTP/1.1 404 Not Found|0d 0a|"; depth:24; nocase; content:"<script"; nocase; within:512; classtype:web-application-attack; sid:2010517; rev:1;)

Added 2009-12-20 22:53:23 UTC


Topic revision: r2 - 2016-04-10 - JohnNaggets
 
This site is powered by the TWiki collaboration platform Powered by Perl This site is powered by the TWiki collaboration platformCopyright © Emerging Threats