8000 fix(932110): added mshta to denylist by s0md3v · Pull Request #2588 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

fix(932110): added mshta to denylist #2588

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Jun 4, 2022
Merged

fix(932110): added mshta to denylist #2588

merged 2 commits into from
Jun 4, 2022

Conversation

s0md3v
Copy link
Contributor
@s0md3v s0md3v commented May 19, 2022

Issue: SO8TP6N6

Description: mshta is a windows command that can be used to download and run malware.

Fix: Add mshta to the windows commands list (util/regexp-assemble/data/932110.data)

@azurit azurit added the ⭐ bug bounty Comes from our Bug Bounty program label May 19, 2022
@dune73
Copy link
Member
dune73 commented May 20, 2022

CRS Bug Bounty PR assessment

  • Rules affected (list rules): 932110
  • Paranoia Level addressed (1, 2, 3, 4, full or explain): 1
  • FTW passes (yes or no) : Yes
  • Rule(s) picked for solution (correct or not-correct or explain) : correct
  • Risk for false positives (irrelevant, adequate, substantial or explain) : adequate
  • Regular expression quality (inspirational, decent base, needs work, adequate or explain) : adequate
  • Documentation (needs work, adequate or explain) : N/A
  • Tests (none or some or adequate) : adequate
     
  • Verdict (Unusable, inspirational, usable, almost perfect or perfect) : perfect

This is not meant to be final. As a CRS dev, feel free to comment below and edit this form directly. As committer or observer, feel free to comment below with feedback and we will think about updating the assessment accordingly.

@dune73 dune73 changed the title fix(932110) - added mshta to blacklist fix(932110) - added mshta to denylist May 22, 2022
@lifeforms lifeforms merged commit 7813a33 into coreruleset:v4.0/dev Jun 4, 2022
@lifeforms lifeforms changed the title fix(932110) - added mshta to denylist fix(932110): added mshta to denylist Jun 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
⭐ bug bounty Comes from our Bug Bounty program
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants
0