Back to Rule

Rule History

SID: 2008453 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 9Jul 30, 2010, 12:00 PM

ET SCAN Tomcat Auth Brute Force attempt (admin)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET SCAN Tomcat Auth Brute Force attempt (admin)"; flow:to_server,established; threshold: type threshold, track by_src, count 5, seconds 30; http.header; content:"Authorization|3a| Basic YWRtaW46"; fast_pattern; classtype:web-application-attack; sid:2008453; rev:9; metadata:created_at 2010_07_30, confidence Medium, signature_severity Informational, updated_at 2020_04_21;)

Jul 30, 2010, 12:00 PM

Apr 21, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-scan.rules