Versions (6)
Version DetailsCurrent
Rev: 3 • Jul 24, 2025, 5:44 PMATTACK [PTsecurity] FreePBX 13/14 Remote Command Execution
alert http any any -> any any (msg:"ATTACK [PTsecurity] FreePBX 13/14 Remote Command Execution"; flow:to_server; content:"POST"; http_method; nocase; content:"/admin/ajax.php"; http_uri; content:"Content-Type: application/x-www-form-urlencoded"; nocase; http_header; pcre:"/file=[^&]*\x60[^&]*\x60/P"; pcre:"/module=recordings/P"; xbits:isset, FreePBXMaliciousFilenameUpload, track ip_dst; reference:exploitdb, 40232; reference:url, rules.ptsecurity.com; classtype:successful-admin; sid:10000083; rev:3;)
Jul 24, 2025, 5:44 PM
Jul 24, 2025, 5:44 PM
Oct 16, 2025, 10:34 AM
Oct 16, 2025, 10:34 AM
rules/ptopen-attacks.rules