Sagan high stable other

[APACHE] Log4j exploit attempt - CVE-2021-44228

[APACHE] Log4j exploit attempt - CVE-2021-44228

View Source

Detection Logic

alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[APACHE] Log4j exploit attempt - CVE-2021-44228"; content:"jndi
| 3a
| "; content: "{"; content: " 200 "; program: *apache*
| httpd; content:!"Rule"; nocase; content:!"drop"; content:!"tmm"; nocase; default_proto:tcp; default_dst_port: $HTTP_PORT; classtype: web-application-attack; parse_src_ip: 1; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; sid:5005960; rev:3; metadata: mitre_technique_id T1210;)

Field Validations

Loading…

Comments (0)

Loading comments...