r1 - 12 Oct 2011 - 23:30:54 - TWikiGuestYou are here: TWiki >  Main Web > 2010923

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS SaurusCMS? class.writeexcel_worksheet.inc.php class_path Remote File Inclusion Attempt"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/classes/excel/class.writeexcel_worksheet.inc.php?"; nocase; uricontent:"class_path="; nocase; pcre:"/class_path\s*=\s*(https?|ftps?|php)\:\//Ui"; reference:url,www.packetstormsecurity.org/0912-exploits/saurus-rfi.txt; reference:url,doc.emergingthreats.net/2010923; classtype:web-application-attack; sid:2010923; rev:2;)

Added 2011-10-12 19:30:54 UTC

 


alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS SaurusCMS? class.writeexcel_worksheet.inc.php class_path Remote File Inclusion Attempt"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/classes/excel/class.writeexcel_worksheet.inc.php?"; nocase; uricontent:"class_path="; nocase; pcre:"/class_path\s*=\s*(https?|ftps?|php)\:\//Ui"; classtype:web-application-attack; reference:url,www.packetstormsecurity.org/0912-exploits/saurus-rfi.txt; reference:url,doc.emergingthreats.net/2010923; sid:2010923; rev:2;)

Added 2011-09-14 22:44:03 UTC


alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS SaurusCMS? class.writeexcel_worksheet.inc.php class_path Remote File Inclusion Attempt"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/classes/excel/class.writeexcel_worksheet.inc.php?"; nocase; uricontent:"class_path="; nocase; pcre:"/class_path\s*=\s*(https?|ftps?|php)\:\//Ui"; classtype:web-application-attack; reference:url,www.packetstormsecurity.org/0912-exploits/saurus-rfi.txt; reference:url,doc.emergingthreats.net/2010923; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_SaurusCMS; sid:2010923; rev:2;)

Added 2011-02-04 17:30:37 UTC


alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"ET WEB_SPECIFIC_APPS SaurusCMS? class.writeexcel_worksheet.inc.php class_path Remote File Inclusion Attempt"; flow:to_server,established; content:"GET "; depth:4; uricontent:"/classes/excel/class.writeexcel_worksheet.inc.php?"; nocase; uricontent:"class_path="; nocase; pcre:"/class_path\s*=\s*(https?|ftps?|php)\:\//Ui"; classtype:web-application-attack; reference:url,www.packetstormsecurity.org/0912-exploits/saurus-rfi.txt; reference:url,doc.emergingthreats.net/2010923; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/WEB_SPECIFIC_APPS/WEB_SaurusCMS; sid:2010923; rev:2;)

Added 2010-03-10 15:00:57 UTC


Edit | Attach | Printable | Raw View | Backlinks: Web, All Webs | History: r1 | More topic actions
 
Emerging Threats
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback