ET EXPLOIT Splunk Unauthenticated Path Traversal Attempt Inbound (CVE-2024-36991)
Query · suricata
flow:established,to_server;
http.uri;
content:"/modules/"; fast_pattern;
pcre:"/\x2f([A-Z]:\.(\.?(\x2f\x2f?|\x2f\x2f?))){2,}/i";
target:dest_ip;
flow:established,to_server;
http.uri;
content:"/modules/"; fast_pattern;
pcre:"/\x2f([A-Z]:\.(\.?(\x2f\x2f?|\x2f\x2f?))){2,}/i";
target:dest_ip;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.