""ET EXPLOIT Possible iOS Pegasus Safari Exploit (CVE-2016-4657)""

SID: 2023484

Revision: 1

Class Type: attempted-admin

Metadata: affected_product iOS, affected_product Safari, attack_target Mobile_Client, created_at 2016_11_07, cve CVE_2016_4657, deployment Perimeter, performance_impact Low, signature_severity Major, updated_at 2016_11_07

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: $HTTP_PORTS

Destination Network: $HOME_NET

Destination Port: any

Flow: established,from_server

Contents:

  • Value: "+="

  • Value: "Object"

  • Value: "defineProperties"

Within:

PCRE: "/^(?:.|[\s?[\x22\x27])defineProperties\s?\x28/Rsi"

Special Options:

  • file_data

source