Hi folks,
I'm trying to write a custom sig to match on certain values found in an HTTP GET request. The sig uses the service-http engine for TCP on standard WEBPORTS. For the sake of this example, lets say the string I'm looking for it:
first=<somedata>&second=<somedata>&third=<somedata>
In other words, if I see those three argument names (first, second, and third) then I want the sig to fire. The actual values of <somedata> is irrelevant.
The RegEx I'm using is:
((first=).*(&second=).*(&third=).*)
However the sig is firing on requests that just match on seeing "&third" in the HTTP GET. Again, I need -all three- arguments present for the sig to fire.
Any suggestions? Am I on the right track with the regex?
Thanks!!