Back to Rule

Rule History

SID: 2026731 • Source: et/open

Versions (2)

Version DetailsCurrent

Rev: 3Dec 14, 2018, 12:00 PM

ET WEB_SERVER ThinkPHP RCE Exploitation Attempt

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_SERVER ThinkPHP RCE Exploitation Attempt"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/index"; content:"/invokefunction&function=call_user_func_array"; distance:0; fast_pattern; reference:url,www.exploit-db.com/exploits/45978; classtype:attempted-admin; sid:2026731; rev:3; metadata:affected_product PHP, attack_target Web_Server, created_at 2018_12_14, deployment Perimeter, deployment Datacenter, performance_impact Low, signature_severity Major, tag ThinkPHP, updated_at 2020_08_31;)

Dec 14, 2018, 12:00 PM

Aug 31, 2020, 12:00 PM

Dec 14, 2018, 12:00 PM

May 31, 2024, 9:00 PM

rules/emerging-web_server.rules