Back to Rule

Rule History

SID: 2021018 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 4Apr 28, 2015, 12:00 PM

ET EXPLOIT WNR2000v4 HTTP POST RCE Attempt Via Timestamp Discovery

alert http any any -> $HOME_NET any (msg:"ET EXPLOIT WNR2000v4 HTTP POST RCE Attempt Via Timestamp Discovery"; flow:to_server,established; threshold:type both, track by_dst, count 10, seconds 60; http.method; content:"POST"; http.uri; content:"/apply_noauth.cgi"; fast_pattern; http.request_body; content:"timestamp="; reference:url,seclists.org/fulldisclosure/2015/Apr/72; classtype:attempted-admin; sid:2021018; rev:4; metadata:created_at 2015_04_28, confidence Medium, signature_severity Major, updated_at 2020_09_30;)

Apr 28, 2015, 12:00 PM

Sep 30, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-exploit.rules