User Tools

Site Tools


pfsense:suricata:alerts:suricata_http_request_unrecognized_authorization_method

PFSense - Suricata - Alerts - SURICATA HTTP Request unrecognized authorization method

HTTP Basic Authentication is commonly used as a quick and dirty credential harvesting mechanism in low-complexity phishing attacks. These authentication events traversing the network in the clear also subjects the transmitted credentials to theft at any portion of the network path.

HTTP Basic Authentication event can be detected by the presence of the Authentication header in the POST request, followed by the word Basic and a base64 encoded string that is the username and password without any further encryption/obfuscation.

False positive.


Seen

192.168.1.112   	50581 	40.100.29.8   	80

Suppress

#SURICATA HTTP Request unrecognized authorization method
suppress gen_id 1, sig_id 2221034
pfsense/suricata/alerts/suricata_http_request_unrecognized_authorization_method.txt · Last modified: 2021/01/18 09:10 by peter

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki