ET WEB_SPECIFIC_APPS ProjectSend Authentication Bypass Attempt M3 - PHP File Upload Attempt (CVE-2024-11680)
Query · suricata
flow:established,to_server; xbits:isset,ET.ProjectSend.AccountCreation,track ip_dst; http.method; content:"POST"; http.uri; bsize:28; content:"/includes/upload.process.php"; fast_pattern; http.request_body; content:"Content-Disposition|3a 20|form-data|3b 20|name|3d 22|name|22|"; content:"Content-Disposition|3a 20|form-data|3b 20|name|3d 22|file|22 3b 20|filename|3d 22|"; within:200; content:"|3c 3f|"; distance:0; pcre:"/^(?:php|.)/R"; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata xbits
ET.ProjectSend.AccountCreation