07-28-2008 05:53 AM - edited 03-10-2019 04:13 AM
In the past week, I have received a plethera of alerts with this High Level title. After blacklisting the host IP it is back with a different one. I am starting to get concerned because the first IP address that was blacklisted was a hacker.
Can someone tell me if this is a false positive or not?
Or, what is actually setting this sensor off?
07-28-2008 09:46 AM
That signatures fires on a match of an attempt to call the awstats.pl cgi script with a parameter of configdir and a parameter value containing a ";" or "|". It seems pretty unlikely to be a false positive in the sense that it is probably not legitimate traffic. It isn't necessarily a hacker targeting your systems...it may just be a worm or script that scans the Internets looking for vulnerable systems.
Do you use awstats?
07-29-2008 04:04 AM
Not really sure. I don't use it myself but honestly someone inside the network could be. I just get the alerts, do the research, pass-on advice, etc...Thanks for the help.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: