Project

General

Profile

Security #2969

http_header signature do not alert on HTTP response with a single \r\n ending

Added by ajaxtpm ajaxtpm almost 2 years ago. Updated 8 months ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Git IDs:

Description

Signature:
alert http any any -> any any (msg: "'ng1nx' Server header found"; flow: established, from_server; content: "ng1nx"; nocase; http_header; classtype: attempted-admin; sid: 1; rev: 1; )

Pcap attached


Files

ng1nx.pcap (1.01 KB) ng1nx.pcap ajaxtpm ajaxtpm, 05/07/2019 11:25 AM

Related issues

Related to Task #3141: libhtp 0.5.31ClosedVictor JulienActions
Related to Task #3142: libhtp 0.5.31 (4.1.x)ClosedVictor JulienActions
#1

Updated by Victor Julien almost 2 years ago

  • Status changed from New to Assigned
  • Assignee set to Philippe Antoine
  • Target version changed from 4.1.4 to TBD
#2

Updated by Victor Julien almost 2 years ago

  • Affected Versions 4.1.4 added
  • Affected Versions deleted (4.1.5)
#3

Updated by ajaxtpm ajaxtpm over 1 year ago

Hi guys, any update on it ?

#5

Updated by Victor Julien over 1 year ago

  • Status changed from Assigned to Closed
  • Target version deleted (TBD)
#6

Updated by Victor Julien 8 months ago

  • Tracker changed from Bug to Security
  • CVE set to 2019-17420

CVE is technically in libhtp, but as Suricata bundles it we track it here as well.

#7

Updated by Victor Julien 8 months ago

#8

Updated by Victor Julien 8 months ago

  • Related to Task #3142: libhtp 0.5.31 (4.1.x) added
#9

Updated by Victor Julien 8 months ago

  • Target version set to 4.1.5

Also available in: Atom PDF