Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

[Snort-sigs] SID 1330

From: Anton Chuvakin <anton(at)chuvakin.org>
Date: Tue Feb 18 2003 - 22:58:10 EST


# This is a template for submitting snort signature descriptions to

Rule: alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS $HTTP_PORTS (msg:"WEB-ATTACKS wget command attempt"; flow:to_server,established; content:"wget%20";nocase; sid:1330; classtype:web-application-attack; rev:4;)

--
Sid: 1330

--
Summary: A post-compromise behavior indicating the use of a UNIX "wget"
command

-- 
Impact: attacker might have gained an ability to execute commands
remotely on the system and an ability to download file onto the web
server

-- 
Detailed Information: This signature triggers when a UNIX "wget"
command is used over a plain-text (unencrypted) connection on one of
the specified web ports to the target web server. The "wget" command
is used to download a file via HTTP or FTP connection to a UNIX
machine. Using "wget", the attackers might be able to download a local
exploit, IRC daemon or DDoS agent onto the server. The signature looks
for the "wget" command in the URL part of the client to web server
connection and does not indicate whether the command was actually
successful in downloading the files. The presence of the "wget" command
in the URL indicates that an attacker attempted to trick the web
server into executing system in non-interactive mode i.e. without a
valid shell session. Another case when this signature might trigger is
unencrypted HTTP tunneling connection to the server.

-- 
Attack Scenarios: An attacker uses a "wget" command via a web
server connection to load a copy of ptrace exploit onto a Linux
machine. He then executes the exploit over the web and obtains root
access.

--
Ease of Attack: very easy, no exploit software required

-- 
False Positives: the signature will trigger if the string "wget " is
present in the URL requested from the web server, such as a part of a long
URL string.

--
False Negatives: non known

-- 
Corrective Action: check the web server software for vulnerabilities
and possible upgrade the system to the latest version, also
investigate the server for signs of compromise

--
Contributors: Anton Chuvakin <
Do you need help?X
http://www.chuvakin.org> -- Additional References: ------------------------------------------------------- This SF.net email is sponsored by: SlickEdit Inc. Develop an edge. The most comprehensive and flexible code editor you can use. Code faster. C/C++, C#, Java, HTML, XML, many more. FREE 30-Day Trial. www.slickedit.com/sourceforge _______________________________________________ Snort-sigs mailing list Snort-sigs@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/snort-sigs
Received on Tue Feb 18 23:29:11 2003

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:08:24 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library