ET SCAN Tomcat Auth Brute Force attempt (tomcat)
Sourceet/open
CreatedJuly 30, 2010
UpdatedApril 21, 2020
Classificationweb-application-attack
alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET SCAN Tomcat Auth Brute Force attempt (tomcat)"; flow:to_server,established; threshold:type threshold, track by_src, count 5, seconds 30; http.header; content:"Authorization|3a| Basic dG9tY2F0"; fast_pattern; classtype:web-application-attack; sid:2008454; rev:9; metadata:created_at 2010_07_30, confidence Medium, signature_severity Informational, updated_at 2020_04_21;)
Metadata
created at2010_07_30
confidenceMedium
signature severityInformational
updated at2020_04_21
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!