Security #2969
closed
http_header signature do not alert on HTTP response with a single \r\n ending
Added by ajaxtpm ajaxtpm over 5 years ago.
Updated about 4 years ago.
Description
Signature:
alert http any any -> any any (msg: "'ng1nx' Server header found"; flow: established, from_server; content: "ng1nx"; nocase; http_header; classtype: attempted-admin; sid: 1; rev: 1; )
Pcap attached
Files
- Status changed from New to Assigned
- Assignee set to Philippe Antoine
- Target version changed from 4.1.4 to TBD
- Affected Versions 4.1.4 added
- Affected Versions deleted (
4.1.5)
Hi guys, any update on it ?
- Status changed from Assigned to Closed
- Target version deleted (
TBD)
- Tracker changed from Bug to Security
- CVE set to 2019-17420
CVE is technically in libhtp, but as Suricata bundles it we track it here as well.
- Related to Task #3142: libhtp 0.5.31 (4.1.x) added
- Target version set to 4.1.5
Also available in: Atom
PDF