Back to Rule

Rule History

SID: 2022263 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 5Dec 15, 2015, 12:00 PM

ET EXPLOIT Joomla RCE M2 (Serialized PHP in UA)

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Joomla RCE M2 (Serialized PHP in UA)"; flow:established,to_server; http.user_agent; content:"O|3a|"; fast_pattern; pcre:"/^\d+\x3a[^\r\n]*?\{[^\r\n]*?\}/R"; reference:url,blog.sucuri.net/2015/12/remote-command-execution-vulnerability-in-joomla.html; classtype:web-application-attack; sid:2022263; rev:5; metadata:created_at 2015_12_15, confidence Medium, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_11;)

Dec 15, 2015, 12:00 PM

Mar 11, 2024, 12:00 PM

Sep 21, 2024, 3:00 AM

Oct 6, 2025, 4:34 PM

rules/emerging-exploit.rules