Back to Rule

Rule History

SID: 2020732 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 4Mar 24, 2015, 12:00 PM

ET WEB_SPECIFIC_APPS Possible Netscaler SQLi bypass (POST data)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS Possible Netscaler SQLi bypass (POST data)"; flow:established,to_server; content:"POST"; http_method; content:"Content-Type|3a 20|application"; http_raw_header; content:"Content-Type|3a 20|"; http_raw_header; distance:0; pcre:"/(?:(?:S(?:HOW (?:C(?:UR(?:DAT|TIM)E|HARACTER SET)|(?:VARI|T)ABLES)|ELECT (?:FROM|USER))|U(?:NION SELEC|PDATE SE)T|DELETE FROM|INSERT INTO)|S(?:HOW.+(?:C(?:HARACTER.+SET|UR(DATE|TIME))|(?:VARI|T)ABLES)|ELECT.+(?:FROM|USER))|U(?:NION.+SELEC|PDATE.+SE)T|DELETE.+FROM|INSERT.+INTO)/Pmi"; reference:url,seclists.org/fulldisclosure/2015/Mar/95; classtype:attempted-dos; sid:2020732; rev:4; metadata:created_at 2015_03_24, performance_impact Significant, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_06_03;)

Mar 24, 2015, 12:00 PM

Jun 3, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 21, 2025, 10:35 PM

rules/emerging-web_specific_apps.rules