Back to Rule

Rule History

SID: 2026026 • Source: et/open

Versions (5)

Version DetailsCurrent

Rev: 2Aug 23, 2018, 12:00 PM

ET EXPLOIT Apache Struts RCE CVE-2018-11776 POC M2

alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT Apache Struts RCE CVE-2018-11776 POC M2"; flow:to_server,established; http.uri; content:"memberAccess"; content:"allowStaticMethodAccess"; distance:0; content:"java.lang.Runtime@getRuntime().exec("; nocase; fast_pattern; distance:0; content:".getInputStream"; content:"java.io.InputStreamReader"; content:"java.io.BufferedReader"; content:".read"; content:"@org.apache.struts2.ServletActionContext@getResponse"; reference:url,github.com/jas502n/St2-057/blob/master/README.md; reference:cve,2018-11776; classtype:attempted-user; sid:2026026; rev:2; metadata:affected_product Apache_Struts2, attack_target Web_Server, created_at 2018_08_23, cve CVE_2018_11776, deployment Perimeter, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_08_25;)

Aug 23, 2018, 12:00 PM

Aug 25, 2020, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 29, 2025, 9:34 PM

rules/emerging-exploit.rules