Rule Update
21-008 (2021年2月23日)
2021年2月23日
概要
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DCERPC Services
1007596* - Identified Possible Ransomware File Extension Rename Activity Over Network Share
DNS Client
1010771* - DNSmasq DNSSEC Out Of Bounds Write Vulnerability (CVE-2020-25683)
Database Microsoft SQL
1010643* - Microsoft SQL Database Server Possible Login Brute Force Attempt
Directory Server LDAP
1010799 - OpenLDAP Slapd Search Parsing Integer Underflow Vulnerability (CVE-2020-36228)
FTP Server IIS
1010797 - SolarWinds Serv-U FTP Server Stored Cross-Site Scripting Vulnerability Over FTP (CVE-2020-28001)
Hot Rod Client
1009119* - Red Hat JBoss Data Grid Hot Rod Client Insecure Deserialization (CVE-2017-15089)
Memcached
1008916* - Identified Memcached Reflected UDP Traffic
Web Application Common
1010488* - Identified WordPress Database Reset Attempt
1010562* - Mantis Bug Tracker 'verify.php' Remote Password Reset Vulnerability (CVE-2017-7615)
1009310* - Microsoft Exchange Server SSRF Vulnerability (CVE-2018-16793)
Web Application PHP Based
1008858* - Identified Access To 'wp-admin' Directory
Web Server Common
1010796 - Apache Druid Remote Code Execution Vulnerability (CVE-2021-25646)
1010802 - FCKeditor Plugin Arbitrary File Upload Vulnerability (CVE-2008-6178)
1007651* - Identified Absence Of Configured CDN/Reverse Proxy HTTP Header
1010761 - PRTG Network Monitor Command Injection Vulnerability (CVE-2018-9276)
1010804 - SolarWinds Serv-U FTP Server Stored Cross-Site Scripting Vulnerability Over HTTP (CVE-2020-28001)
Web Server HTTPS
1010795* - Joomla CMS Cross-Site Scripting Vulnerability (CVE-2021-23124)
1010772* - Microsoft Exchange Remote Code Execution Vulnerability (CVE-2020-17132)
Web Server Miscellaneous
1008747* - Adobe ColdFusion RMI Registry Insecure Deserialization (CVE-2017-11284)
1008840* - Apache CouchDB '_config' Command Execution Vulnerability
Web Server Oracle
1010752* - Oracle Coherence Server T3 Protocol Insecure Deserialization Vulnerability (CVE-2020-14756)
Web Server SharePoint
1010794* - Microsoft SharePoint Workflow Deserialization Of Untrusted Data Remote Code Execution Vulnerability (CVE-2021-24066)
Zoho ManageEngine
1010774 - Identified WebNMS Framework Server Sensitive File Access (ATT&CK T1552.001)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
DCERPC Services
1007596* - Identified Possible Ransomware File Extension Rename Activity Over Network Share
DNS Client
1010771* - DNSmasq DNSSEC Out Of Bounds Write Vulnerability (CVE-2020-25683)
Database Microsoft SQL
1010643* - Microsoft SQL Database Server Possible Login Brute Force Attempt
Directory Server LDAP
1010799 - OpenLDAP Slapd Search Parsing Integer Underflow Vulnerability (CVE-2020-36228)
FTP Server IIS
1010797 - SolarWinds Serv-U FTP Server Stored Cross-Site Scripting Vulnerability Over FTP (CVE-2020-28001)
Hot Rod Client
1009119* - Red Hat JBoss Data Grid Hot Rod Client Insecure Deserialization (CVE-2017-15089)
Memcached
1008916* - Identified Memcached Reflected UDP Traffic
Web Application Common
1010488* - Identified WordPress Database Reset Attempt
1010562* - Mantis Bug Tracker 'verify.php' Remote Password Reset Vulnerability (CVE-2017-7615)
1009310* - Microsoft Exchange Server SSRF Vulnerability (CVE-2018-16793)
Web Application PHP Based
1008858* - Identified Access To 'wp-admin' Directory
Web Server Common
1010796 - Apache Druid Remote Code Execution Vulnerability (CVE-2021-25646)
1010802 - FCKeditor Plugin Arbitrary File Upload Vulnerability (CVE-2008-6178)
1007651* - Identified Absence Of Configured CDN/Reverse Proxy HTTP Header
1010761 - PRTG Network Monitor Command Injection Vulnerability (CVE-2018-9276)
1010804 - SolarWinds Serv-U FTP Server Stored Cross-Site Scripting Vulnerability Over HTTP (CVE-2020-28001)
Web Server HTTPS
1010795* - Joomla CMS Cross-Site Scripting Vulnerability (CVE-2021-23124)
1010772* - Microsoft Exchange Remote Code Execution Vulnerability (CVE-2020-17132)
Web Server Miscellaneous
1008747* - Adobe ColdFusion RMI Registry Insecure Deserialization (CVE-2017-11284)
1008840* - Apache CouchDB '_config' Command Execution Vulnerability
Web Server Oracle
1010752* - Oracle Coherence Server T3 Protocol Insecure Deserialization Vulnerability (CVE-2020-14756)
Web Server SharePoint
1010794* - Microsoft SharePoint Workflow Deserialization Of Untrusted Data Remote Code Execution Vulnerability (CVE-2021-24066)
Zoho ManageEngine
1010774 - Identified WebNMS Framework Server Sensitive File Access (ATT&CK T1552.001)
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.