ET EXPLOIT D-Link 850L Password Extract Attempt
Sourceet/open
CreatedOctober 25, 2017
UpdatedAugust 13, 2020
Classificationattempted-recon
alert http any any -> $HOME_NET any (msg:"ET EXPLOIT D-Link 850L Password Extract Attempt"; flow:to_server,established; urilen:11; http.method; content:"POST"; http.uri; content:"/hedwig.cgi"; fast_pattern; http.request_body; content:"DEVICE.ACCOUNT"; reference:url,blogs.securiteam.com/index.php/archives/3364; classtype:attempted-recon; sid:2024913; rev:3; metadata:attack_target IoT, created_at 2017_10_25, deployment Perimeter, signature_severity Major, updated_at 2020_08_13;)
References
Metadata
attack targetIoT
created at2017_10_25
deploymentPerimeter
signature severityMajor
updated at2020_08_13
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!