ET EXPLOIT F5 BIG-IP rsync cmi authorized_keys access attempt

SID: 2019088Rev: 40 views
History
Sourceet/open
CreatedAugust 29, 2014
UpdatedOctober 8, 2019
Classificationattempted-admin
alert tcp any any -> any 873 (msg:"ET EXPLOIT F5 BIG-IP rsync cmi authorized_keys access attempt"; flow:to_server,established; content:"cmi/var/ssh/root/authorized_keys"; fast_pattern; flowbits:set,ET.F5.key; reference:url,www.security-assessment.com/files/documents/advisory/F5_Unauthenticated_rsync_access_to_Remote_Root_Code_Execution.pdf; classtype:attempted-admin; sid:2019088; rev:4; metadata:created_at 2014_08_29, signature_severity Major, updated_at 2019_10_08;)

Metadata

created at2014_08_29
signature severityMajor
updated at2019_10_08

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!