Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Emerging Threats sid:2012843 detecting the recent Wordpress brute force attacks -

$
0
0

# This Ruleset is EmergingThreats Open optimized for snort-2.9.0.

#by Jaime Blasco
#
#alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE HTTP 401 Unauthorized"; flow:from_server,established; content:"401"; http_stat_code; threshold: type both, count 1, seconds 300, track by_dst; reference:url,doc.emergingthreats.net/2009345; classtype:attempted-recon; sid:2009345; rev:7;)

#by Jaime Blasco
#
#alert tcp $HTTP_SERVERS $HTTP_PORTS -> $EXTERNAL_NET any (msg:"ET ATTACK_RESPONSE Frequent HTTP 401 Unauthorized - Possible Brute Force Attack"; flow:from_server,established; content:"401";  http_stat_code;  threshold:type both, track by_dst, count 30, seconds 60; reference:url,doc.emergingthreats.net/2009346; classtype:attempted-recon; sid:2009346; rev:7;)



Viewing all articles
Browse latest Browse all 8064

Trending Articles