mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
20cb4400dc
"There's a snake in my Tomcat!" When malicious serialized objects started showing up at Sunnyside Server Farm, Security Sheriff Haag rounded up a posse of new detections to keep the web applications safe. This PR delivers: - Two new best friends: tomcat_session_file_upload_attempt and tomcat_session_deserialization_attempt - A brand new playset: "Apache Tomcat Session Deserialization Attacks" analytic story - No more crying when the bad toys try to upload .session files - The claw of justice comes down when suspicious JSESSIONID cookies appear Remember what Security Ranger Haag always says: "To HTTP response codes and beyond!"