ET WEB_SPECIFIC_APPS N-able N-central Session ID Disclosure
Query · suricata
flow:established,to_client; flowbits:isset,ET.N_able_N_central.CVE_2025_9316; http.response_body; content:"ns1|3a|sessionHelloResponse"; fast_pattern; content:"|3c 2f|sessionid|3e|"; nocase; distance:0; pcre:"/\x3e\d+\x3c\x2fsessionid\x3e/i"; http.stat_code; content:"200"; target:dest_ip;
Rule dependencies
⚠ Higher-order rule. It fires on other rules' alerts, not on raw events, so it cannot fire on its own. Deploy the rules it depends on too.
Depends on
-
correlates · Suricata flowbits
ET.N_able_N_central.CVE_2025_9316