Versions (6)
Version DetailsCurrent
Rev: 3 • Jul 24, 2025, 5:44 PMATTACK [PTsecurity] Webexservice remote privileged command execution (CVE-2018-15442)
alert smb any any -> any 445 (msg:"ATTACK [PTsecurity] Webexservice remote privileged command execution (CVE-2018-15442)"; flow:established, to_server, no_stream; content:"SMB"; depth:8; content:"|05 00 00|"; distance:0; content:"|13 00|"; distance:19; within:3; content:"s|00|o|00|f|00|t|00|w|00|a|00|r|00|e|00|-|00|u|00|p|00|d|00|a|00|t|00|e|00|"; nocase; distance:0; flowbits:isset, CVE.2018-15442.Probe; reference:url, webexec.org; reference:cve, 2018-15442; reference:url, rules.ptsecurity.com; classtype:attempted-admin; sid:10003983; rev:3;)
Jul 24, 2025, 5:44 PM
Jul 24, 2025, 5:44 PM
Oct 16, 2025, 10:34 AM
Oct 16, 2025, 10:34 AM
rules/ptopen-attacks.rules