""ET EXPLOIT Apache Spark RPC - Unauthenticated RegisterApplication Request - RCE Attempt (CVE-2020-9480)""

SID: 2035005

Revision: 2

Class Type: attempted-admin

Metadata: attack_target Server, created_at 2022_01_28, cve CVE_2020_9480, deployment Internal, deployment Datacenter, signature_severity Major, updated_at 2022_01_28

Reference:

Protocol: tcp

Source Network: any

Source Port: any

Destination Network: $HOME_NET

Destination Port: any

Flow: established,to_server

Contents:

  • Value: "org.apache.spark.deploy.DeployMessages$RegisterApplication"

  • Value: "spark.driver.port="

  • Value: "-XX:OnOutOfMemoryError="

Within:

PCRE: "/^\d+..(?:[\x60\x3b\x7c]|%60|%3b|%7c|%26|(?:[\x3c\x3e\x24]|%3c|%3e|%24)(?:\x28|%28))-XX:OnOutOfMemoryError=/R"

Special Options:

source