Back to Rule

Rule History

SID: 2025823 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 3Jul 10, 2018, 12:00 PM

ET EXPLOIT D-Link DIR601 2.02 Credential Disclosure

alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link DIR601 2.02 Credential Disclosure"; flow:established,to_server; http.uri; content:"/my_cgi.cgi"; http.request_body; content:"request=no_auth"; content:"request=load_settings"; content:"table_name=admin_user"; fast_pattern; content:"table_name=user_user"; content:"table_name=wireless_settings"; content:"table_name=wireless_security"; content:"table_name=wireless_wpa_settings"; reference:url,exploit-db.com/exploits/45002/; classtype:attempted-recon; sid:2025823; rev:3; metadata:attack_target IoT, created_at 2018_07_10, deployment Datacenter, performance_impact Low, confidence High, signature_severity Major, updated_at 2020_08_25;)

Jul 10, 2018, 12:00 PM

Aug 25, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-exploit.rules