Snort mailing list archives
SID 18773
From: vincent () ragosta net
Date: Thu, 12 Jan 2012 09:34:10 -0500
What exactly is Snort SID 18773 attempting to alert on? The rule name is 'BLACKLIST URI for known malicious URI - /stat.htm" and contains some very specific content clauses. When I follow the URL specified by one of these alerts, it points to a 1x1 pixel GIF image. Is this part of a known exploit? Thanks, Vincent
------------------------------------------------------------------------------ RSA(R) Conference 2012 Mar 27 - Feb 2 Save $400 by Jan. 27 Register now! http://p.sf.net/sfu/rsa-sfdev2dev2
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists sourceforge net https://lists.sourceforge.net/lists/listinfo/snort-sigs http://www.snort.org Please visit http://blog.snort.org for the latest news about Snort!
Current thread:
- SID 18773 vincent (Jan 12)
- Re: SID 18773 JJ Cummings (Jan 12)
- Re: SID 18773 Alex Kirk (Jan 17)