""ET WEB_SERVER Possible HP OpenView Network Node Manager ovalarm.exe CGI Buffer Overflow Attempt""

SID: 2010704

Revision: 8

Class Type: web-application-attack

Metadata: created_at 2010_07_30, cve CVE_2009_4179, confidence High, updated_at 2011_01_20

Reference:

  • cve

  • 2009-4179

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: "GET"

  • Value: "/OvCgi/ovalarm.exe"

  • Value: "OVABverbose="

  • Value: "Accept-Language|3A 20|"

  • Value: !"|0A|"

Within: 100

PCRE:

Special Options:

  • nocase

  • http_method

  • nocase

  • http_uri

  • nocase

  • http_uri

  • nocase

source