SHELLCODE: Linux/x86 Shadow File World Read/Write Enable over HTTP

This signature detects shellcode designed to modify permissions on the etc/shadow file that stores sensitive password hashes on most Linux systems being sent over HTTP. Attempts to execute such shellcode could be part of an ongoing malicious attack.

Short Name
SHELLCODE:LINUX:CHMDSDW-HTTP
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
SHELLCODE
Keywords
Enable File HTTP Linux/x86 Read/Write Shadow World over
Release Date
09/20/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?