TROJAN: Telnet User "satori"
This signature detects the password "satori" used to log in to a backdoor user account (previously installed on a UNIX host by a Trojan or worm) through Telnet to local server port 23. Attackers can remotely compromise the system.
Extended Description
Linux systems infected by Satori contain backdoor utilities that allow attackers to gain complete administrative control of a system.
References
CVE: CVE-1999-0660
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
8.8