Back to Rule

Rule History

SID: 3300356 • Source: pawpatrules

Versions (2)

Version DetailsCurrent

Rev: 2Oct 31, 2022, 12:00 PM

🐾 - 🚨 👀 ipinfo.io lookup public IP address from local network - Possible Leak 🚱

alert tls $HOME_NET any -> $EXTERNAL_NET any (msg:"🐾 - 🚨 👀 ipinfo.io lookup public IP address from local network - Possible Leak 🚱"; flow:to_server, stateless; threshold: type limit, track by_src,count 1, seconds 3600; tls_sni; content:"ipinfo.io"; nocase; metadata:created_at 2022_10_31, updated_at 2024_08_08; sid:3300356; rev:2; classtype:external-ip-check;)

Oct 31, 2022, 12:00 PM

Aug 8, 2024, 12:00 PM

Feb 21, 2024, 4:00 PM

May 29, 2025, 11:12 PM

rules/PAW-PATRULES_LEAKS.rules