Back to Rule

Rule History

SID: 2049278 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 1Nov 21, 2023, 12:00 PM

ET WEB_SPECIFIC_APPS Tinycontrol LAN Controller v3 Request for lk3_settings.bin Backup File

alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS Tinycontrol LAN Controller v3 Request for lk3_settings.bin Backup File"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/lk3_settings.bin"; fast_pattern; reference:url,www.exploit-db.com/exploits/51731; reference:url,www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5786.php; classtype:credential-theft; sid:2049278; rev:1; metadata:attack_target ICS, created_at 2023_11_21, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2023_11_21; target:dest_ip;)

Nov 21, 2023, 12:00 PM

Nov 21, 2023, 12:00 PM

Nov 21, 2023, 10:00 PM

Aug 18, 2025, 8:35 PM

rules/emerging-web_specific_apps.rules