alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (
msg:"ET EXPLOIT Apache Struts RCE CVE-2018-11776 POC M1";
flow:to_server,established;
http.uri;
content:"memberAccess";
content:"allowStaticMethodAccess"; distance:0;
content:"java.lang.Runtime|25|40getRuntime().exec("; nocase; fast_pattern; distance:0;
content:".getInputStream()";
content:"java.io.InputStreamReader(";
content:"java.io.BufferedReader(";
content:".read(";
content:"org.apache.struts2.ServletActionContext";
content:"getResponse().getWriter()";
reference:url,github.com/jas502n/St2-057/blob/master/README.md;
reference:cve,2018-11776;
classtype:attempted-user;
sid:2026025; rev:2;
metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2018_08_23, cve CVE_2018_11776, deployment Perimeter, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_08_25;
)