|
|
@ -47,5 +47,14 @@ Example::
|
|
|
|
http_uri = "GET /en/somestring&dGVzdAo=¬_base64"
|
|
|
|
http_uri = "GET /en/somestring&dGVzdAo=¬_base64"
|
|
|
|
|
|
|
|
|
|
|
|
Rule:
|
|
|
|
Rule:
|
|
|
|
alert http any any -> any any (msg:"Example"; content:"somestring"; base64_decode:bytes 8, offset 1, relative; \
|
|
|
|
alert http any any -> any any (msg:"Example"; http.uri; content:"somestring"; \
|
|
|
|
http_uri; base64_content; content:"test"; sid:10001; rev:1;)
|
|
|
|
base64_decode:bytes 8, offset 1, relative; \
|
|
|
|
|
|
|
|
base64_data; content:"test"; sid:10001; rev:1;)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Buffer content:
|
|
|
|
|
|
|
|
http_uri = "GET /en/somestring&dGVzdAo=¬_base64"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Rule:
|
|
|
|
|
|
|
|
alert http any any -> any any (msg:"Example"; content:"somestring"; http_uri; \
|
|
|
|
|
|
|
|
base64_decode:bytes 8, offset 1, relative; \
|
|
|
|
|
|
|
|
base64_data; content:"test"; sid:10001; rev:1;)
|
|
|
|