ATTACK [PTsecurity] Webexservice remote priveleged command execution (CVE-2018-15442)

SID: 10003983Rev: 10 views
Sourceptresearch/attackdetection
CreatedDecember 13, 2021
UpdatedDecember 13, 2021
Classificationattempted-admin
alert tcp any any -> any 445 (msg:"ATTACK [PTsecurity] Webexservice remote priveleged command execution (CVE-2018-15442)"; flow:established, to_server, no_stream; content:"SMB"; depth:8; content:"|05 00 00|"; distance:0; content:"|13 00|"; distance:19; within:3; content:"s|00|o|00|f|00|t|00|w|00|a|00|r|00|e|00|-|00|u|00|p|00|d|00|a|00|t|00|e|00|"; nocase; distance:0; reference:url, webexec.org; reference:cve, 2018-15442; flowbits:isset, CVE.2018-15442.Probe; classtype:attempted-admin; reference:url, github.com/ptresearch/AttackDetection; sid:10003983; rev:1;)

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!