Snort mailing list archives
WEB-MISC long basic authorization string
From: "Semerjian, Ohanes" <Semerjian.Ohanes () wcom com au>
Date: Tue, 8 Apr 2003 10:45:14 +0800
Dear all, I'm getting the " WEB-MISC long basic authorization string " from source IPs which are part of our internal network to one host. This host is an internal web server whom our MIS changed the IP address just before these alerts start flow. Now I've checked the signature definition which shows that it takes consideration of the payload. What I would like to know that if there is other legitimate traffic could fire up this signature..?coz I don't think a big number of machines on the network are trying to attack this one host..? Would appreciate your thoughts alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS 80 (msg:"WEB-MISC long basic authorization string"; flags:A+; content:"Authorization\: Basic "; nocase; dsize:>1000; classtype:attempted-dos; reference:bugtraq,3230; sid:1260; rev:2;) Best Regards Ohanes Semerjian
Current thread:
- WEB-MISC long basic authorization string Semerjian, Ohanes (Apr 07)
- <Possible follow-ups>
- RE: WEB-MISC long basic authorization string Matt Yackley (Apr 08)
- RE: WEB-MISC long basic authorization string Semerjian, Ohanes (Apr 08)