""ET WEB_CLIENT Possible HTTP 503 XSS Attempt (External Source)""

SID: 2010527

Revision: 6

Class Type: web-application-attack

Metadata: affected_product Web_Browsers, affected_product Web_Browser_Plugins, attack_target Client_Endpoint, created_at 2010_07_30, deployment Perimeter, signature_severity Major, tag Web_Client_Attacks, updated_at 2019_09_27

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: from_server,established

Contents:

  • Value: "503"

  • Value: "Service Unavailable"

  • Value: "<script" Depth: 280

Within:

PCRE:

Special Options:

  • http_stat_code

  • nocase

  • file_data

  • nocase

source