new snort sig
alert tcp $EXTERNAL_NET $HTTP_PORTS -> $HOME_NET any (msg:"BLEEDING-EDGE Microsoft Internet Explorer Window() Possible Code Execution"; flow:established,from_server; content:"window"; nocase; pcre:"/[=\:'"\s]window\s*\(\s*\)/i";
reference:url,secunia.com/advisories/15546; reference:cve,2005-1790; classtype:attempted-user; sid:111199999; rev:1; )
credit and thanks to Blake Hartstein @ Demarc Security for the fast signature on this!




Reply With Quote