Technical analysis: Barracuda Email Security Gateway by Quentin Olagne
ID: d90d8b8e-aa7e-5c31-b8bb-93b5d71f53e0
STIX ID: report--d90d8b8e-aa7e-5c31-b8bb-93b5d71f53e0
Feed Name: Vectra AI Blog
On May 23, 2023 Barracuda disclosed CVE-2023-2868 affecting its Email Security Gateway; attackers were exploiting it in the wild. The report dissects a Rapid7 PoC that crafts a malformed TAR archive (splitting a long filename/command across headers) to evade a Suricata Emerging Threats rule looking for paired backtick/single-quote sequences. The authors identified the detection gap, rewrote and submitted an improved M2 detection rule (SID 2048146 rev 2), and provide recommendations to ensure updated rulesets are deployed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
