ET POLICY localtunnel Connection Setup Attempt
Sourceet/open
CreatedDecember 4, 2017
UpdatedSeptember 16, 2020
Classificationpolicy-violation
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET POLICY localtunnel Connection Setup Attempt"; flow:established,to_server; http.host; content:"localtunnel.me"; fast_pattern; endswith; http.header_names; content:"|0d 0a|host|0d 0a|accept"; depth:14; content:!"User-Agent"; content:!"Host"; content:!"Referer"; content:!"Accept"; reference:url,localtunnel.github.io/www/; classtype:policy-violation; sid:2025116; rev:4; metadata:attack_target Client_and_Server, created_at 2017_12_04, deployment Perimeter, confidence High, signature_severity Minor, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_09_16;)
References
Metadata
attack targetClient_and_Server
created at2017_12_04
deploymentPerimeter
confidenceHigh
signature severityMinor
tagDescription_Generated_By_Proofpoint_Nexus
updated at2020_09_16
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!