Project

General

Profile

Actions

Bug #229

closed

Gzip & Chunk encoding issue

Added by Gurvinder Singh over 13 years ago. Updated over 12 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Affected Versions:
Effort:
Difficulty:
Label:

Description

The follow sig goes along with scanner-clean.pcap:
alert tcp any any > any any (msg:"EID FAKEAV scanner page encountered
- Initializing Virus Protection System..."; content:"Virus Protection
System"; classtype:bad-unknown; sid:5600106; rev:2;)

This sig goes with the iframe.pcap:
alert tcp any any -> any any (msg:"MALVERTISING hidden iframe served
by nginx 2"; content:"iframe"; nocase; classtype:bad-unknown;
sid:5600066; rev:1;)

failed to fire on the attached pcaps.


Files

iframe.pcap (1.6 KB) iframe.pcap Gurvinder Singh, 08/25/2010 02:22 PM
scanner-clean.pcap (287 KB) scanner-clean.pcap Gurvinder Singh, 08/25/2010 02:22 PM
out.log (12.6 KB) out.log Gurvinder Singh, 08/28/2010 10:44 PM
Actions

Also available in: Atom PDF