On this page
Atomicorp WAF Rule 330034
Rule Summary
- Rule ID: 330034
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Unauthorized Vulnerability Scanner detected
- Observed CWEs: None documented
- Revision: 14
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request headers
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule is triggered when known vulnerability scanners and attack tools attempt to connect to the server. The following tools are detected:
- nsauditor
- n-stealth
- nessus
- network-services-auditor
- nikto
- nmap
- black window
- brutus
- bilbo
- webinspect
- webroot
- pmafind
- paros
- pavuk
- cgichk
- jasscois
- NASL scripts
- metis
- webtrends security analyzer
- w3af
- zemu attack tool
- springenwerk
- arachni
- acunetix
- havij attack tool
Troubleshooting
False Positives
There are no known false positives with this rule, however if you find that this rule is triggered for a client that is not using a vulnerability scanner or attack tool please report this to us using the procedure documented in the Reporting_False_Positives page.
Tuning Guidance
If you wish to allow connections from vulnerability scanners or attack tools we recommend you whitelist the source IPs as opposed to disabling this rule. Please see the Tuning the Atomicorp WAF Rules page for more information.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
No selected related public CVE research notes are currently published.
Documentation Source
- Original wiki page: WAF 330034
- Source revision: 3916
- Source revision date: 2013-09-03