Back to Rule

Rule History

SID: 2036444 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 1May 2, 2022, 12:00 PM

ET WEB_SERVER Possible SSRF Attempt Inbound Using Common Dork M17

alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SERVER Possible SSRF Attempt Inbound Using Common Dork M17"; flow:to_server,established; http.uri; content:"?return="; fast_pattern; pcre:"/^(?:\w{2,6}://|\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})/R"; classtype:misc-activity; sid:2036444; rev:1; metadata:attack_target Web_Server, created_at 2022_05_02, deployment Perimeter, deployment Internal, deprecation_reason Performance, performance_impact Moderate, confidence Medium, signature_severity Informational, updated_at 2022_05_02;)

May 2, 2022, 12:00 PM

May 2, 2022, 12:00 PM

Sep 21, 2024, 3:00 AM

Sep 21, 2024, 3:00 AM

rules/emerging-web_server.rules