ET EXPLOIT D-Link 850L Password Extract Attempt

SID: 2024913Rev: 30 views
History
Sourceet/open
CreatedOctober 25, 2017
UpdatedAugust 13, 2020
Classificationattempted-recon
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link 850L Password Extract Attempt"; flow:to_server,established; urilen:11; http.method; content:"POST"; http.uri; content:"/hedwig.cgi"; fast_pattern; http.request_body; content:"DEVICE.ACCOUNT"; reference:url,blogs.securiteam.com/index.php/archives/3364; classtype:attempted-recon; sid:2024913; rev:3; metadata:attack_target IoT, created_at 2017_10_25, deployment Perimeter, signature_severity Major, updated_at 2020_08_13;)

Metadata

attack targetIoT
created at2017_10_25
deploymentPerimeter
signature severityMajor
updated at2020_08_13

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!