Project

General

Profile

Actions

Security #2969

closed

http_header signature do not alert on HTTP response with a single \r\n ending

Added by ajaxtpm ajaxtpm over 4 years ago. Updated about 3 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:
Severity:

Description

Signature:
alert http any any -> any any (msg: "'ng1nx' Server header found"; flow: established, from_server; content: "ng1nx"; nocase; http_header; classtype: attempted-admin; sid: 1; rev: 1; )

Pcap attached


Files

ng1nx.pcap (1.01 KB) ng1nx.pcap ajaxtpm ajaxtpm, 05/07/2019 11:25 AM

Related issues 2 (0 open2 closed)

Related to Suricata - Task #3141: libhtp 0.5.31ClosedVictor JulienActions
Related to Suricata - Task #3142: libhtp 0.5.31 (4.1.x)ClosedVictor JulienActions
Actions #1

Updated by Victor Julien over 4 years ago

  • Status changed from New to Assigned
  • Assignee set to Philippe Antoine
  • Target version changed from 4.1.4 to TBD
Actions #2

Updated by Victor Julien over 4 years ago

  • Affected Versions 4.1.4 added
  • Affected Versions deleted (4.1.5)
Actions #3

Updated by ajaxtpm ajaxtpm about 4 years ago

Hi guys, any update on it ?

Actions #5

Updated by Victor Julien about 4 years ago

  • Status changed from Assigned to Closed
  • Target version deleted (TBD)
Actions #6

Updated by Victor Julien about 3 years ago

  • Tracker changed from Bug to Security
  • CVE set to 2019-17420

CVE is technically in libhtp, but as Suricata bundles it we track it here as well.

Actions #7

Updated by Victor Julien about 3 years ago

Actions #8

Updated by Victor Julien about 3 years ago

  • Related to Task #3142: libhtp 0.5.31 (4.1.x) added
Actions #9

Updated by Victor Julien about 3 years ago

  • Target version set to 4.1.5
Actions

Also available in: Atom PDF