<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FPs Sig 5432 Script in HTTP header in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691491#M92335</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It actually fires on &lt;SCRIPT&gt; ... &lt;/SCRIPT&gt; in the header. There's probably more to the alert context tat what you have pasted there. If you enable "Produce Verbose Alert" as an action for that sig, you will see the trigger packet in the alert, and that should contain the "script ... /script"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Sep 2006 16:34:02 GMT</pubDate>
    <dc:creator>wsulym</dc:creator>
    <dc:date>2006-09-21T16:34:02Z</dc:date>
    <item>
      <title>FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691490#M92334</link>
      <description>&lt;P&gt;This signature appears to be looking for script markers in the header, but is firing on just the presence of 'script' which is not a problem.  Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;000000  47 45 54 20 2F 42 75 72  73 74 69 6E 67 53 63 72  GET /BurstingScr&lt;/P&gt;&lt;P&gt;000010  69 70 74 2F 61 64 64 69  6E 65 79 65 2E 6A 73 20  ipt/addineye.js &lt;/P&gt;&lt;P&gt;000020  48 54 54 50 2F 31 2E 31  0D                       HTTP/1.1.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:14:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691490#M92334</guid>
      <dc:creator>jkell</dc:creator>
      <dc:date>2019-03-10T10:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691491#M92335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It actually fires on &lt;SCRIPT&gt; ... &lt;/SCRIPT&gt; in the header. There's probably more to the alert context tat what you have pasted there. If you enable "Produce Verbose Alert" as an action for that sig, you will see the trigger packet in the alert, and that should contain the "script ... /script"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2006 16:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691491#M92335</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2006-09-21T16:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691492#M92336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, changed and re-baited the hook.  Awaiting the next fish...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2006 19:05:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691492#M92336</guid>
      <dc:creator>jkell</dc:creator>
      <dc:date>2006-09-21T19:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691493#M92337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got one:  the script is in the Referer: tag (sort of).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Sep 2006 19:47:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691493#M92337</guid>
      <dc:creator>jkell</dc:creator>
      <dc:date>2006-09-21T19:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691494#M92338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, doesn't look malicious at all. Not that I was having all sorts of luck finding out much about it, but from what I could find, looks like   a click thru banner ad. Just looks like its feeding some benign information into the javascript banner generator.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will update the benign triggers section of the signasture accordingly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2006 19:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691494#M92338</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2006-09-22T19:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691495#M92339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isn't the signature designed to basically just look at the URI content?  Can you adjust the regexp to locate script tags before the &lt;CR&gt;&lt;LF&gt; terminator?&lt;/LF&gt;&lt;/CR&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2006 22:46:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691495#M92339</guid>
      <dc:creator>jkell</dc:creator>
      <dc:date>2006-09-22T22:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: FPs Sig 5432 Script in HTTP header</title>
      <link>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691496#M92340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, 5432-0 is looking for script tags anywhere in the entire header. You may be thinking of the other XSS sigs. 5232-x sigs look for script in the uri and arguments only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Sep 2006 14:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fps-sig-5432-script-in-http-header/m-p/691496#M92340</guid>
      <dc:creator>wsulym</dc:creator>
      <dc:date>2006-09-23T14:47:36Z</dc:date>
    </item>
  </channel>
</rss>

