""GPL SQL Oracle iSQLPlus login.uix username overflow attempt""

SID: 2102703

Revision: 4

Class Type: web-application-attack

Metadata: created_at 2010_09_23, updated_at 2012_09_12

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: to_server,established

Contents:

  • Value: "/login.uix"

  • Value: "username="

  • Value: !"|0A|"

Within: 250

PCRE: "/username=[^&\x3b\r\n]{250}/smi"

Special Options:

  • http_uri

  • nocase

  • nocase

source