Sagan medium stable other

[WEB-ATTACKS] SQL Power Injector SQL Injection User Agent Detected

[WEB-ATTACKS] SQL Power Injector SQL Injection User Agent Detected

View Source

Detection Logic

alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[WEB-ATTACKS] SQL Power Injector SQL Injection User Agent Detected"; content: "User-Agent"; content: "SQL Power Injector"; content:"Security tool (Make sure it is used with the administrator consent)"; parse_src_ip: 1; parse_dst_ip: 2; reference:url,www.sqlpowerinjector.com/index.htm; reference:url,en.wikipedia.org/wiki/Sql_injection; reference:url,doc.emergingthreats.net/2009769; xbits: set,recon,track ip_src,expire 86400; default_proto:tcp; default_dst_port: $HTTP_PORT; classtype:attempted-recon; sid:5001812; rev:3;)

Field Validations

Loading…

Comments (0)

Loading comments...