""ET POLICY Suspicious Malformed Double Accept Header""

SID: 2008975

Revision: 14

Class Type: policy-violation

Metadata: created_at 2010_07_30, updated_at 2018_10_03

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: any

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "Accept|3a| Accept|3a| "

  • Value: !"-DRM"

  • Value: !"buhphone.ru|0d 0a|"

  • Value: !"Host|3a 20|www.backupmaker.com"

  • Value: !"ati.com|0d 0a|"

  • Value: !"amd.com|0d 0a|"

Within:

PCRE:

Special Options:

  • http_header

  • http_header

  • http_header

  • http_header

  • nocase

  • http_header

  • nocase

  • http_header

source