Back to Rule

Rule History

SID: 2032078 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 2Mar 16, 2021, 12:00 PM

ET WEB_CLIENT Leaf PHPMailer Accessed on External Server

alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET WEB_CLIENT Leaf PHPMailer Accessed on External Server"; flow:established,to_client; file.data; content:"V5 PHPMailer</title>"; fast_pattern; content:"for=|22|senderName|22|>Sender Name</label>"; content:"type=|22|file|22 20|name=|22|attachment[]|22 20|id=|22|attachment[]|22|"; classtype:web-application-attack; sid:2032078; rev:2; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2021_03_16, deployment Perimeter, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2021_03_16;)

Mar 16, 2021, 12:00 PM

Mar 16, 2021, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 15, 2025, 9:36 PM

rules/emerging-web_client.rules