Sagan high stable other

[APACHE] CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF

[APACHE] CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF

View Source

Detection Logic

alert any $EXTERNAL_NET any -> $HOME_NET any (msg:"[APACHE] CVE-2014-6271 Attempt In HTTP Headers Line Continuation Evasion LF"; content:"
| 28 29 0a 20 7b
| "; program: *apache*
| httpd; xbits: set, exploit_attempt ,track ip_src, expire 86400; parse_src_ip: 1; reference:url,www.invisiblethreat.ca/2014/09/cve-2014-6271/; default_proto:tcp; default_dst_port: $HTTP_PORT; classtype:attempted-admin; sid:5002210; rev:8; metadata: mitre_technique_id T1210;)

Field Validations

Loading…

Comments (0)

Loading comments...