Back to Rule

Rule History

SID: 2020731 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 4Mar 24, 2015, 12:00 PM

ET WEB_SPECIFIC_APPS Possible Netscaler SQLi bypass (URI data)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Netscaler SQLi bypass (URI data)"; flow:established,to_server; content:"Content-Type|3a 20|application"; http_raw_header; content:"Content-Type|3a 20|"; distance:0; http_raw_header; pcre:"/(?:(?:S(?:HOW (?:C(?:UR(?:DAT|TIM)E|HARACTER SET)|(?:VARI|T)ABLES)|ELECT (?:FROM|USER))|U(?:NION SELEC|PDATE SE)T|DELETE FROM|INSERT INTO)|S(?:HOW.+(?:C(?:HARACTER.+SET|UR(DATE|TIME))|(?:VARI|T)ABLES)|ELECT.+(?:FROM|USER))|U(?:NION.+SELEC|PDATE.+SE)T|DELETE.+FROM|INSERT.+INTO)/Ui"; reference:url,seclists.org/fulldisclosure/2015/Mar/95; classtype:attempted-dos; sid:2020731; rev:4; metadata:created_at 2015_03_24, performance_impact Significant, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_06_03;)

Mar 24, 2015, 12:00 PM

Jun 3, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 20, 2025, 8:34 PM

rules/emerging-web_specific_apps.rules