CVE-2019-10098 Exploitation Attempt

Detects open redirect vulnerability in mod_rewrite configuration.

Sigma rule (View on GitHub)

 1title: CVE-2019-10098 Exploitation Attempt
 2id: 326da16d-5f47-4895-bb0f-2a15dfb87c81
 3status: experimental
 4description: Detects open redirect vulnerability in mod_rewrite configuration. 
 5references:
 6  - https://0day.work/open-redirects-in-improperly-configured-mod_rewrite-rules-poc-for-cve-2019-10098/
 7author: Loginsoft Research Unit 
 8date: 2020/06/17
 9logsource:
10 product: apache
11 category: webserver
12detection:
13  selection:
14    sc-status: 302
15    c-uri|contains: 
16      - '/%0A'
17      - '/%0a'
18  condition: selection
19level: medium```

References

to-top