""ET WEB_SPECIFIC_APPS Symantec Messaging Gateway 9.5.3-3 - Arbitrary file download 2""

SID: 2016119

Revision: 2

Class Type: attempted-user

Metadata: created_at 2012_12_04, updated_at 2012_12_29

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HOME_NET

Destination Port: 41080

Flow: to_server,established

Contents:

  • Value: "/brightmail/admin/restore/download.do?"

  • Value: "&localBackupFileSelection="

  • Value: "|2e 2e 2f|" Depth: 200

Within:

PCRE:

Special Options:

  • http_uri

  • http_uri

source