THL DETECT Ivanti-Connect-Secure CVE-2023-46805 Auth-Bypass Path Traversal to system-information (Initial Access Attempt)
Sourcehunters-ledger
Filehunters-ledger.rules
CreatedJuly 27, 2026
UpdatedJuly 27, 2026
Classificationweb-application-attack
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"THL DETECT Ivanti-Connect-Secure CVE-2023-46805 Auth-Bypass Path Traversal to system-information (Initial Access Attempt)"; flow:established,to_server ; http.uri; content:"/api/v1/totp/user-backup-code/../../system/system-information"; classtype:web-application-attack; sid:3500169; rev:1; metadata:author The_Hunters_Ledger, date 2026-07-17, reference https://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/ ;)
Metadata
authorThe_Hunters_Ledger
date2026-07-17
referencehttps://the-hunters-ledger.com/hunting-detections/seasia-gov-exploitation-toolkit-144-172-106-236-detections/
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!