Short Name |
HTTP:EXPLOIT:SMALL-FIRST-DATA |
---|---|
Severity |
Warning |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Small First Packet |
Release Date |
2008/05/01 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects a very small first data packet during an HTTP session. This may be an indication of "Session Slicing" which is an IPS evasion technique. The HTTP specification defines the minimum request size to be 15 bytes.