EmergingThreats
>
Main Web
>
2013809
(2017-08-08,
TWikiGuest
)
E
dit
A
ttach
alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET ACTIVEX Oracle
AutoVue
?
Activex Insecure method (
SaveViewStateToFile
?
)"; flow:to_client,established; content:"
]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B6FCC215-D303-11D1-BC6C-0000C078797F/si"; reference:url,exploit-db.com/exploits/18016; classtype:attempted-user; sid:2013809; rev:3; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, attack_target Client_Endpoint, deployment Perimeter, tag
ActiveX
?
, signature_severity Major, created_at 2011_10_31, updated_at 2016_07_01;)
Added 2017-08-07 21:07:05 UTC
Please enter documentation, comments, false positives, or concerns with this signature. Press the Attach button below to add samples or Pcaps.
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"ET ACTIVEX Oracle
AutoVue
?
Activex Insecure method (
SaveViewStateToFile
?
)"; flow:to_client,established; file_data; content:"
]*classid\s*=\s*[\x22\x27]?\s*clsid\s*\x3a\s*\x7B?\s*B6FCC215-D303-11D1-BC6C-0000C078797F/si"; reference:url,exploit-db.com/exploits/18016; classtype:attempted-user; sid:2013809; rev:3;)
Added 2011-10-31 17:03:28 UTC
E
dit
|
A
ttach
|
P
rint version
|
H
istory
: r1
|
B
acklinks
|
R
aw View
|
WYSIWYG
|
M
ore topic actions
Topic revision: r1 - 2017-08-08
-
TWikiGuest
Main
Log In
or
Register
Main Web
Create New Topic
Index
Search
Changes
Preferences
User Reference
ATasteOfTWiki
TextFormattingRules
Signature Reference
WebRss
Feed
EmergingFAQ
Copyright © Emerging Threats