Back to Rule

Rule History

SID: 2010519 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 5Jul 30, 2010, 12:00 PM

ET WEB_SERVER Possible HTTP 405 XSS Attempt (Local Source)

alert http $HTTP_SERVERS any -> $EXTERNAL_NET 1024: (msg:"ET WEB_SERVER Possible HTTP 405 XSS Attempt (Local Source)"; flow:from_server,established; content:"HTTP/1.1 405 Method Not Allowed|0d 0a|"; depth:33; nocase; content:"<script"; nocase; within:512; classtype:web-application-attack; sid:2010519; rev:5; metadata:created_at 2010_07_30, deprecation_reason Performance, performance_impact Significant, confidence Medium, signature_severity Minor, updated_at 2024_04_10;)

Jul 30, 2010, 12:00 PM

Apr 10, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-web_server.rules