Project

General

Profile

Actions

Bug #214

closed

Fail to alert on sid 2009800

Added by Josh Smith over 14 years ago. Updated over 14 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

Suricata fails to alert on sid 2009800.

alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"ET POLICY Carbonite.com Backup Software Leaking MAC Address"; flow:established,to_server; content:"GET "; depth:4; uricontent:"/manage.old/sun/signup.aspx?MACAddresses=MAC"; nocase; uricontent:"ShowCount="; nocase; classtype:policy-violation; reference:url,doc.emergingthreats.net/2009800; reference:url,www.emergingthreats.net/cgi-bin/cvsweb.cgi/sigs/POLICY/POLICY_Carbonite; sid:2009800; rev:3;)


Files

2009800.pcap (677 Bytes) 2009800.pcap Josh Smith, 07/16/2010 02:32 PM
emerging-all.rules (4.61 MB) emerging-all.rules emerging-all.rules used for this test Will Metcalf, 07/20/2010 07:59 AM
Actions

Also available in: Atom PDF