Documents

The following setup guides have been contributed by members of the Snort Community for your use. Comments and questions on these documents should be submitted directly to the author by clicking on their names below.


Latest rule documents - Search
1:63813
This rule looks for path/directory traversal characters in HTTP requests to vulnerable versions of SolarWinds Serv-U.
1:63812
Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive. Impact: CVSS base score 7.5 CVSS impact score 6.4 CVSS exploitability score 10.0 confidentialityImpact PARTIAL integrityImpact PARTIAL availabilityImpact PARTIAL Details: Ease of Attack:
1:63811
This rule looks for requests to an HTTP endpoint that create a backdoor on the Zyxel NAS326.
1:63810
This rule looks for requests to an HTTP endpoint that create a backdoor on the Zyxel NAS326.
1:63809
This rule looks for requests to an HTTP endpoint that create a backdoor on the Zyxel NAS326.
1:63806
This rule detects a crafted HTTP request commonly used by the Grandoreiro strain of malware