ET WEB_SERVER Possible SQL Injection Attempt char() Danmec related in HTTP URI
Query · suricata
flow:established,to_server;
http.request_line;
content:"CHAR("; nocase;
pcre:"/^[0-9]{2,3}\)char\([^\x0d\x0a\x20]{98}/Ri";
flow:established,to_server;
http.request_line;
content:"CHAR("; nocase;
pcre:"/^[0-9]{2,3}\)char\([^\x0d\x0a\x20]{98}/Ri";
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.