I've noticed a spike in alerts from our deployed USGs related to the following signatures:
Rule_id=1 [type=Sig(1055101)] WEB Apache HTTPD mod_proxy_ajp Denial Of Service (CVE-2011... Action: Rule_id=1 [type=Sig(1058307)] WEB Apache Struts Wildcard Matching OGNL Code Execution
Anyone else noticing this? The odd part is so far having looked up the destination IPs, one is very vague and has abuse reports with no reverse DNS, another also has no reverse DNS, but the third is Earthlink's webmail (which this client sadly uses).
Still digging but figured I'd see what others are noticing.
↧