Back to Rule

Rule History

SID: 2002896 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 8Jul 30, 2010, 12:00 PM

ET EXPLOIT Symantec Scan Engine Request Password Hash

alert http $EXTERNAL_NET any -> $HOME_NET 8004 (msg:"ET EXPLOIT Symantec Scan Engine Request Password Hash"; flow:established,to_server; http.method; content:"POST"; nocase; http.uri; content:"/xml.xml"; fast_pattern; nocase; http.request_body; content:"<request"; nocase; content:"<key "; nocase; reference:cve,2006-0230; reference:bugtraq,17637; classtype:attempted-recon; sid:2002896; rev:8; metadata:created_at 2010_07_30, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_13;)

Jul 30, 2010, 12:00 PM

Mar 13, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Dec 15, 2025, 10:34 PM

rules/emerging-exploit.rules