Back to Rule

Rule History

SID: 10002475 • Source: ptrules/open

Versions (6)

Version DetailsCurrent

Rev: 1Jul 24, 2025, 5:44 PM

ATTACK [PTsecurity] Possible Dnsmasq <2.78 DHCPv6 Sensitive info leak (CVE-2017-14494)

alert udp any any -> any 547 (msg:"ATTACK [PTsecurity] Possible Dnsmasq <2.78 DHCPv6 Sensitive info leak (CVE-2017-14494)"; flow:no_stream; content:"|0C|"; depth:1; content:"|00 09|"; distance:33; within:2; content:"|00 01|"; distance:24; within:2; byte_test:2, >, 2, 0, relative, big; isdataat:!3,relative; reference:cve, 2017-14494; reference:url, security.googleblog.com/2017/10/behind-masq-yet-more-dns-and-dhcp.html; reference:url, rules.ptsecurity.com; classtype:attempted-admin; sid:10002475; rev:1;)

Jul 24, 2025, 5:44 PM

Jul 24, 2025, 5:44 PM

Oct 16, 2025, 10:34 AM

Oct 16, 2025, 10:34 AM

rules/ptopen-attacks.rules