Network Security Monitoring Rules [12-13 March]

William Lee·2025년 3월 12일

Security Onion

OWASP ZAP

IDS Engine (Warning only)

Snort

Sniffer Mode
Packet Logging Mode
NIDS Mode
IPS (Drop)

Suricata

Multicore / Multithread
LUA language

Bro

OSSEC

Argus

Netsniff-NG

Event Analysis Tool

Sguil

Quick Query
Transcript / Wireshark
Update Event Status
Report

Snorby

Squert

ELSA

Extracting Patterns by Vulnerability Category

Path Traversal
To access files and directories stored outside the web root directory

SQL Injection

Directory Browsing

Remote OS Command Injection

Cross Site Scripting

Remote Code Execution - Shellshock

CVE 2012 1823

CVE-2012-1823 is a vulnerability in PHP-CGI where command-line options can be improperly processed within the URI. This issue arises due to insufficient parameter validation in the cgi_main.c file within the /sapi/cgi/ directory of the PHP source code. Exploiting this flaw allows attackers to execute arbitrary commands by injecting specific options in the request URI, potentially leading to remote code execution or unauthorized system access.

profile
Cyber Security Graduate

0개의 댓글