Hi freinds Are the content options sequantial to? like the uricontent opton?? or no?
Aditya
>Do uricontent's get checked in sequentially like content options? In particular sid 1072 has two >uricontent options. According to most of the advisories these two uricontents need to appear in the >order they are defined ie "GET /.nsf/../somefile". However I am receiving alerts for URI >like "GET /../prog.nsf/data/file". Is this expected behaviour?
>alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-MISC Lotus Domino directory >traversal"; uricontent:".nsf/"; uricontent:"../"; nocase; flow:t>o_server,established; >reference:cve,CVE-2001-0009; reference:bugtraq,2173; classtype:web-application-attack; sid:1072; >rev:6;)
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 11:49:55 EDT