THL DETECT MultiVector-192.3.1.116 JWT alg-none Authentication Bypass Attempt (Forged Token Header)
Sourcehunters-ledger
Filehunters-ledger.rules
CreatedJuly 27, 2026
UpdatedJuly 27, 2026
Classificationattempted-admin
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"THL DETECT MultiVector-192.3.1.116 JWT alg-none Authentication Bypass Attempt (Forged Token Header)"; flow:established,to_server ; http.header; content:"Bearer eyJhbGciOiJub25lIn0"; classtype:attempted-admin; sid:3500164; rev:2; metadata:author The_Hunters_Ledger, date 2026-07-21, reference https://the-hunters-ledger.com/hunting-detections/multivector-ecommerce-rce-toolkit-192-3-1-116-detections/ ;)
Metadata
authorThe_Hunters_Ledger
date2026-07-21
referencehttps://the-hunters-ledger.com/hunting-detections/multivector-ecommerce-rce-toolkit-192-3-1-116-detections/
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!