SHELLCODE: Linux unlink autofsck Execute

This signature detects shellcode designed to remove autofsck script from Linux systems. This script ensures filesystem consistency by prompting users to complete routine checks. Deletion of such scripts could prove fatal if a system is infected with malware.

Short Name
SHELLCODE:LINUX:UNLINK
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SHELLCODE
Keywords
Execute Linux autofsck unlink
Release Date
05/08/2013
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
Port
TCP/1-79,81-442,444-3127,3129-7999,8001-8079,8081-65535
False Positive
Unknown

Found a potential security threat?