""ET WEB_SERVER Possible CVE-2014-6271 Attempt""
SID: 2022028
Revision: 1
Class Type: attempted-admin
Metadata: created_at 2015_11_04, cve CVE_2014_6271, updated_at 2015_11_04
Reference:
Protocol: tcp
Source Network: any
Source Port: any
Destination Network: $HTTP_SERVERS
Destination Port: $HTTP_PORTS
Flow: established,to_server
Contents:
-
Value: " HTTP/1."
-
Value: "|28 29 20 7b|"
Within:
PCRE: "/^[^\r\n]*?HTTP\/1(?:(?!\r?\n\r?\n)[\x20-\x7e\s]){1,500}\n[\x20-\x7e]{1,100}\x3a[\x20-\x7e]{0,500}\x28\x29\x20\x7b/s"
Special Options: