Rapid7 Labs critical experimental sigma

Attempt to Exploit CVE-2024-0204

Detects attempts to exploit an unauthenticated bypass in GoAnywhere MFT (CVE-2024-0204).

View Source

Detection Logic

{
  "selection": {
    "c-uri": "/goanywhere/images/..;/wizard/InitialAccountSetup.xhtml",
    "c-method": "GET"
  },
  "condition": "selection"
}

False Positives

  • scanning tools like vulnerability scanning tools

Field Validations

Loading…

Comments (0)

Loading comments...