""ET WEB_SERVER WEBSHELL JSP/Backdoor Shell Access""

SID: 2022348

Revision: 2

Class Type: successful-admin

Metadata: created_at 2016_01_12, updated_at 2016_01_14

Reference:

Protocol: tcp

Source Network: $EXTERNAL_NET

Source Port: any

Destination Network: $HTTP_SERVERS

Destination Port: $HTTP_PORTS

Flow: established,to_server

Contents:

  • Value: ".war?cmd="

  • Value: "&winurl="

  • Value: "&linurl="

Within:

PCRE: "/.war\?cmd=[a-zA-Z0-9+/=]+&winurl=[a-zA-Z0-9+/=]&linurl=[a-zA-Z0-9+/=]/U"

Special Options:

  • http_uri

  • http_uri

  • http_uri

source