Back to Rule

Rule History

SID: 2010920 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 10Jul 30, 2010, 12:00 PM

ET WEB_SERVER Exploit Suspected PHP Injection Attack (cmd=)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Exploit Suspected PHP Injection Attack (cmd=)"; flow:established,to_server; http.method; content:"GET"; nocase; http.uri; content:".php?"; nocase; content:"cmd="; fast_pattern; nocase; pcre:"/[&?]cmd=[^\x26\x28]*(?:cd|\;|echo|cat|perl|curl|wget|id|uname|t?ftp)/i"; reference:cve,2002-0953; classtype:web-application-attack; sid:2010920; rev:10; metadata:created_at 2010_07_30, cve CVE_2002_0953, confidence Medium, signature_severity Major, updated_at 2024_01_03;)

Jul 30, 2010, 12:00 PM

Jan 3, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-web_server.rules